Splunk Search

Top 10 values and other to be Grouped in "OTHERS"..??

SanthoshSreshta
Contributor

Hi All,

I am bit new to this Splunk
I am able to get top 10 values but not able to group other ( not in top 10 ) in another value. Can any one provide the command to get the scenario.
I have used sourcetype="Churn Data_CSV" Churn="True." | top limit=10 state to get top 10 values. I want 11th column which contains other values.

Regards,
Santhosh.

1 Solution

krish3
Contributor

I believe you are looking for this..

your search string |top limit=10 state useother=1

View solution in original post

krish3
Contributor

I believe you are looking for this..

your search string |top limit=10 state useother=1

SanthoshSreshta
Contributor

Wow.!!
That much simple.
tQ. Thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...