Splunk Search

How to use an additional conditional with the top command (ex: count > 10) and add a sequential number column to the table?

okug
New Member

Hi,

I have questions about the top command.

First one is pretty simple.
How I can add sequential number column in top result table?

2nd one is.
Is there any way to use an additional conditional to top command? I want to do something like:
top limit=30 and percent > 1 ....
top limit=50 and count >= 10 ....

Thanks!

0 Karma
1 Solution

satishsdange
Builder

| top limit=30 xxx | where count > 10

View solution in original post

pradeepkumarg
Influencer

Try this..

| top limit=30 | eval s_no =1 | accum s_no
| top limit=30 | where percent > 1
| top limit=30 | where count >= 10
0 Karma

satishsdange
Builder

| top limit=30 xxx | where count > 10

okug
New Member

Great! Thanks!!
Any idea for 1st question?

0 Karma

ppablo
Retired

Hi @okug

Try and see if the answer on this post can help answer your 1st question.
http://answers.splunk.com/answers/216542/how-to-add-a-first-column-to-number-each-row-in-a.html

0 Karma

okug
New Member

Thanks!

top limit=30 foo| where percent >= 1 | streamstats count as row | fields row,foo,count,percent

worked.

0 Karma

ppablo
Retired

Hi @okug

Great 🙂 glad it worked!

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...