Splunk Search

How to show the top command with distinct value?

igschloessl
Explorer

I've got proxy logs and I want to show the top 5 urls and for that the count of distinct users who tried to access it.
I tried the following search command

index=proxy
| eval dc_user=[search* stats dc(user) by url| return $dc_user]
| top dest_host limit=5
| table dest_host dc_user

How can I get this work?
I also wanted to add the count of the url and the percentage.

Thank you in advance.

Tags (1)

cpmoone
Engager

Does this do what you need?

index=proxy
| eventstats dc(user) as unique_users by url
| top url 
| sort 5 - count
| table url, unique_users, count, percent

somesoni2
Revered Legend

Give this a try

index=proxy 
| stats dc(user) as UniqUsers count by dest_host
| sort 5 -count
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...