Splunk Search
Highlighted

TOP 10 values

Path Finder

I have a sample data from email logs where we have from and message size.
how can I extract "Top ten sending addresses by message size"
attaching sample data snapshot.

alt text

Tags (2)
0 Karma
Highlighted

Re: TOP 10 values

SplunkTrust
SplunkTrust

Check out the top command. Also, the sort command has an option to limit the number of results.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: TOP 10 values

Ultra Champion

In this case:

your search
| table from size
| sort 10 - size
0 Karma