Splunk Search

Limit for chart with split-by clause ?

JensT
Communicator

Hi,

i have this search:

index=foo | eval length=length(_raw) | chart eval(sum(length)/1024/1024) as MiB by application

Now i just want the first 15 apps. But using "limit=15" says:
The following options were specified but have no effect when a split-by clause is not provided:limit.

How can i use limit?

Regards, Jens

Tags (2)
0 Karma
1 Solution

RicoSuave
Builder

so are you doing:
index=foo | eval length=length(_raw) | chart limit=15 eval(sum(length)/1024/1024) as MiB by application

?

View solution in original post

0 Karma

rmanrique
Path Finder

To limit the queries with the "chart" command, just use the "sort" command and then indicate the number of lines you want to display:

index=foo | eval length=length(_raw) | chart eval(sum(length)/1024/1024) as MiB by application | sort 15 -MiB

0 Karma

russellliss
Path Finder

It appears that limit only works for timecharts, but you should be able to get the answer you are wanting by doing a reverse sort, to get the "top" entries to appear first, and then do a head, to show only the first x rows.

So your search string should be :

index=foo | eval length=length(_raw) | chart eval(sum(length)/1024/1024) as MiB by application | sort -MiB | head 15

combinatorics
Explorer

I have the exact same issue. I'm doing this query, but get that exact error message.

index=myindex sourcetype=access_combined host=somehost | chart limit=7 count by root

Leaving out the limit=7 works fine, but gives a chart that has about 20 items, which isn't important for my dashboard, and doesn't look very good. I just need the top 6-8 context roots displayed with HTTP request counts.

0 Karma

RicoSuave
Builder

so are you doing:
index=foo | eval length=length(_raw) | chart limit=15 eval(sum(length)/1024/1024) as MiB by application

?

0 Karma

JensT
Communicator

Thats what i would like to do, but thats not working.

-- Jens

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...