Hi, I am looking to display results a certain way and want to know if this is possible in Splunk. We have proxy logs that contain URLs and client IPs. I want to group by URLs (top 20) and display all IPs that connected to them. I want the output to look something like this,,
Url CountOfConnections
..Client IP list
google.com 3
...192.168.1.2
...192.168.1.7
...192.168.1.3
yahoo.com 2
...192.168.1.2
...192.168.1.3
Basically a visually simple way to distinguish urls and clients.
Doing something like "top 20 url ip" doesn't look good for this type of report. Thanks!
would this be what you want?
| stats values(ip) as IPs by url
so add another function.
| stats values(ip) as IPs dc(ip) as ipCount by url | sort - ipCount
Thanks, but that's no quite it. I already tried it before. It doesn't give me a count for each site, and also I can't figure out a way to sort it by # of IPs per url.