Splunk Search

Trying to do a Top command per hourly intervals

Johnnerz
Engager

Hi There,

I have a search that shows the top 2 Id's that have the most payments processed in each country. I'm trying to make this search give me these results per hour

The search itself works as expected in the below format, I just want to give the results in an hourly interval instead 

`index` "Payment Status"
| rex "status:(?P<status>APPROVED|DECLINED)"
| search status=APPROVED OR status=DECLINED
| top limit=2 id by country, status

I've tried putting it into a timechart and also using the span but it keeps asking for a function and I don't know how to rewrite the above into hourly spans.

Labels (3)
0 Karma
1 Solution

saravanan90
Contributor

This may help...

`index` "Payment Status"
| rex "status:(?P<status>APPROVED|DECLINED)"
| search status=APPROVED OR status=DECLINED
| bin span=1h _time
| top 2 id by _time country status

View solution in original post

saravanan90
Contributor

This may help...

`index` "Payment Status"
| rex "status:(?P<status>APPROVED|DECLINED)"
| search status=APPROVED OR status=DECLINED
| bin span=1h _time
| top 2 id by _time country status

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...