Splunk Search

How to show table with highest values in a column

maniu1609
Path Finder

Timechart output shows me table with two columns. column one is _time and column two is interger values.
example:
_time count
2018-05-22 10:07:16 4
2018-05-22 10:08:09 4
2018-05-22 10:07:45 4
2018-05-22 10:06:54 2
2018-05-22 10:07:11 1

Now I want display table with highest count column. Since 4 is the highest value in column "count", I want to display those rows having highest count 4 as below :

_time count
2018-05-22 10:07:16 4
2018-05-22 10:08:09 4
2018-05-22 10:07:45 4

How I can achieve this. Thanks in advance!!

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Try like this

your current search giving field _time and count 
| eventstats max(count) as max
| where count=max | fields - max

View solution in original post

somesoni2
Revered Legend

Try like this

your current search giving field _time and count 
| eventstats max(count) as max
| where count=max | fields - max

maniu1609
Path Finder

Great!!. Thanks a lot!!

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...