Hi I am using this search in order to find out what Bluecoat filter categories cause the most bandwidth utilization
index=bluecoat mysearch | fields sc_filter_category sc_bytes | eventstats sum(sc_bytes) as allbytes | stats sum(sc_bytes) as "totalbytes" by sc_filter_category,allbytes | eval "Bandwidth(MB)"= round(totalbytes/(1024*1024),2) | eval Percentage=(totalbytes/allbytes)*100 | sort 10 -"Bandwidth(MB)"
Tis seems to work fine.
My result is as an example a table like this
sc_filter_category allbytes, Bandwidth(MB), Percentage
category1, 100, 20,20
category2,100, 11,11
category3,100,10,10
category4,100,5,5
So what I would like to do is then in a second search be able to list what top two URLs cause the most bandwidth for each category.
The output would look like this
Category Top-URLs
category1 www.abc.com, www.def.com, www.ghi.com
category2 www.abc1.com, www.def1.com, www.ghi1.com
I am not able to find out how to search dynamically using the result of the first search... any help appreciated.
... View more