Hello everybody,
I am getting data in "index=test", I am trying to get top 10 Calling userid's with there call count.
device_type="device1" so far i have
thanks
@splunkuseradmin ,
Try
index="collab_uc_cdr" NOT INTEGER NOT globalCallID_callId
( sourcetype=cisco_cdr OR sourcetype=cisco_cdr-* OR sourcetype=cucm_cdr ) ( globalCallId_ClusterID=AMR-Corp-CCM11XX OR globalCallId_ClusterID=AMR-Corp-CCM12XX OR globalCallId_ClusterID=AMR-Corp-CCM13XX OR globalCallId_ClusterID=AMR-Corp-CCM14XX OR globalCallId_ClusterID=AMR-Corp-CCM15XX ) duration>0 device_type="Jabber" eventtype="outgoing_call"
|stats count by globalCallId_ClusterID,callingPartyUnicodeLoginUserID
|sort - count |head 10