Splunk Search
Highlighted

Is it possible to get both rare and top results in the same search result table?

Contributor

Hi,

I want to know if it's possible to get rare and top value on the same table search.

index=_internal |top limit=5 sourcetype
index=_internal |rare limit=5 sourcetype

thx

Tags (3)
0 Karma
Highlighted

Re: Is it possible to get both rare and top results in the same search result table?

Splunk Employee
Splunk Employee

Hmm. Here is one way:

index=_internal
| top limit=2 sourcetype
| append [ search index=_internal | rare limit=2 sourcetype ]

View solution in original post

Highlighted

Re: Is it possible to get both rare and top results in the same search result table?

Contributor

thx aljhonson

0 Karma
Highlighted

Re: Is it possible to get both rare and top results in the same search result table?

Splunk Employee
Splunk Employee

np @sfatnass

0 Karma