Splunk Search

Which fields correspond these metrics, count and percent?

palisetty
Communicator

I have two fields on the event list. I have used Top command for that, I have got two fields and count and percent.

index="main" host="web_application"
| top JSESSIONID uri

For which corresponding fields are these metrics count and percent for?

JSESSIONID  uri count   percent
SD1SL10FF2ADFF4960  /oldlink?&JSESSIONID=SD1SL10FF2ADFF4960 30  0.011426
SD4SL10FF5ADFF4959  /oldlink?&JSESSIONID=SD4SL10FF5ADFF4959 26  0.009902
SD2SL1FF6ADFF4962   /oldlink?&JSESSIONID=SD2SL1FF6ADFF4962  26  0.009902
SD0SL2FF3ADFF4961   /oldlink?&JSESSIONID=SD0SL2FF3ADFF4961  26  0.009902
SD7SL5FF6ADFF4959   /oldlink?&JSESSIONID=SD7SL5FF6ADFF4959  24  0.009140
SD6SL6FF8ADFF4964   /oldlink?&JSESSIONID=SD6SL6FF8ADFF4964  24  0.009140
Tags (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The results of top are for both fields together. That is, each pair of JSESSIONSID and uri values.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The results of top are for both fields together. That is, each pair of JSESSIONSID and uri values.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...