Splunk Search

Top 10 per group

alucarddjin
Path Finder

Is there a way to get the top 10 count for a number of groupings eg:

Col1    Col2    Count
G1        SG1     10
G1        SG2     8
G1        SG3     6
G2        SG4     21
G2        SG5     5
G2        SG6     1

So I have the top 10 for G1 then the top 10 for G2

0 Karma
1 Solution

woodcock
Esteemed Legend

Just do this:

... | sort 0 - Count
| dedup 10 Col1

View solution in original post

0 Karma

woodcock
Esteemed Legend

Just do this:

... | sort 0 - Count
| dedup 10 Col1
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...