Splunk Search

Search for then report top 20 requested dest_host?

New Member

I am trying to write a query that will search for all the requested destination hosts and then take the search results and produce a visual report (graphic) showing the top 20 or so destinations. I'm very new to splunk so any/all help would be very appreciated. Thank you.

Tags (1)
0 Karma
1 Solution

Contributor

It depends what your logfile and its entry looks like, but it could be something similar like:

  • < your_search > | chart count by dest_host | sort -count

If you have your result, click on the "Build report" button on the upper right corner to create a graphical report

View solution in original post

Contributor

It depends what your logfile and its entry looks like, but it could be something similar like:

  • < your_search > | chart count by dest_host | sort -count

If you have your result, click on the "Build report" button on the upper right corner to create a graphical report

View solution in original post