Don't have a specific example, but would like to understand for my education.
For example, I don't understand what COULD be the difference between listing two fields in the top command versus using the "by" clause. See the following basic examples:
index=sales sourcetype=vendor_sales
| top vendor product name
vs.
index=sales sourcetype=vendor_sales |
top vendor by product name
The answer to your question can be found from this Accepted Answer in Splunk Answers.
https://answers.splunk.com/answers/243063/when-you-feed-multiple-field-names-to-the-top-comm.html
The answer to your question can be found from this Accepted Answer in Splunk Answers.
https://answers.splunk.com/answers/243063/when-you-feed-multiple-field-names-to-the-top-comm.html
I think this old post can help answer your question.
Have you looked at the examples in the docs?