Splunk Search

How to use an additional conditional with the top command (ex: count > 10) and add a sequential number column to the table?

okug
New Member

Hi,

I have questions about the top command.

First one is pretty simple.
How I can add sequential number column in top result table?

2nd one is.
Is there any way to use an additional conditional to top command? I want to do something like:
top limit=30 and percent > 1 ....
top limit=50 and count >= 10 ....

Thanks!

0 Karma
1 Solution

satishsdange
Builder

| top limit=30 xxx | where count > 10

View solution in original post

pradeepkumarg
Influencer

Try this..

| top limit=30 | eval s_no =1 | accum s_no
| top limit=30 | where percent > 1
| top limit=30 | where count >= 10
0 Karma

satishsdange
Builder

| top limit=30 xxx | where count > 10

okug
New Member

Great! Thanks!!
Any idea for 1st question?

0 Karma

ppablo
Retired

Hi @okug

Try and see if the answer on this post can help answer your 1st question.
http://answers.splunk.com/answers/216542/how-to-add-a-first-column-to-number-each-row-in-a.html

0 Karma

okug
New Member

Thanks!

top limit=30 foo| where percent >= 1 | streamstats count as row | fields row,foo,count,percent

worked.

0 Karma

ppablo
Retired

Hi @okug

Great 🙂 glad it worked!

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...