Don't have a specific example, but would like to understand for my education.
For example, I don't understand what COULD be the difference between listing two fields in the top command versus using the "by" clause. See the following basic examples:
index=sales sourcetype=vendor_sales
| top vendor product name
index=sales sourcetype=vendor_sales |
top vendor by product name
The answer to your question can be found from this Accepted Answer in Splunk Answers.
The answer to your question can be found from this Accepted Answer in Splunk Answers.
I think this old post can help answer your question.
Have you looked at the examples in the docs?