Splunk Search

How to show the top command with distinct value?

igschloessl
Explorer

I've got proxy logs and I want to show the top 5 urls and for that the count of distinct users who tried to access it.
I tried the following search command

index=proxy
| eval dc_user=[search* stats dc(user) by url| return $dc_user]
| top dest_host limit=5
| table dest_host dc_user

How can I get this work?
I also wanted to add the count of the url and the percentage.

Thank you in advance.

Tags (1)

cpmoone
Engager

Does this do what you need?

index=proxy
| eventstats dc(user) as unique_users by url
| top url 
| sort 5 - count
| table url, unique_users, count, percent

somesoni2
Revered Legend

Give this a try

index=proxy 
| stats dc(user) as UniqUsers count by dest_host
| sort 5 -count
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...