Splunk Search

Top 10 per group

alucarddjin
Path Finder

Is there a way to get the top 10 count for a number of groupings eg:

Col1    Col2    Count
G1        SG1     10
G1        SG2     8
G1        SG3     6
G2        SG4     21
G2        SG5     5
G2        SG6     1

So I have the top 10 for G1 then the top 10 for G2

0 Karma
1 Solution

woodcock
Esteemed Legend

Just do this:

... | sort 0 - Count
| dedup 10 Col1

View solution in original post

0 Karma

woodcock
Esteemed Legend

Just do this:

... | sort 0 - Count
| dedup 10 Col1
0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...