Don't have a specific example, but would like to understand for my education.
For example, I don't understand what COULD be the difference between listing two fields in the top command versus using the "by" clause. See the following basic examples:
| top vendor product name
index=sales sourcetype=vendor_sales |
top vendor by product name
The answer to your question can be found from this Accepted Answer in Splunk Answers.
View solution in original post
I think this old post can help answer your question.
Have you looked at the examples in the docs?