Splunk Search

order result High to Low

sdewar83
Path Finder

I have a simple query, listing event codes by host:

index=wineventlog sourcetype=WinEventLog:Security
Stats count by EventCode, host

I'd like to order the results so that it shows either the top 10 highest count event codes (e.g 100 of 4625, 80 of 4264, etc) per host.
Or at least displays the count column in a highest to lowest fashion, per host. At the moment it displays all the info, but in no specific ordering. I'd like it to be more readily obvious which are the most common errors happening on hosts in t he time period i'm searching.

Any assistance appreciated!

0 Karma
1 Solution

Sukisen1981
Champion

so you add this - sort host,- count

View solution in original post

0 Karma

Sukisen1981
Champion

so you add this - sort host,- count

0 Karma

sdewar83
Path Finder

perfect! worked like a charm.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...