Splunk Search

How to show the top command with distinct value?

igschloessl
Explorer

I've got proxy logs and I want to show the top 5 urls and for that the count of distinct users who tried to access it.
I tried the following search command

index=proxy
| eval dc_user=[search* stats dc(user) by url| return $dc_user]
| top dest_host limit=5
| table dest_host dc_user

How can I get this work?
I also wanted to add the count of the url and the percentage.

Thank you in advance.

Tags (1)

cpmoone
Engager

Does this do what you need?

index=proxy
| eventstats dc(user) as unique_users by url
| top url 
| sort 5 - count
| table url, unique_users, count, percent

somesoni2
Revered Legend

Give this a try

index=proxy 
| stats dc(user) as UniqUsers count by dest_host
| sort 5 -count
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...