Splunk Search

How to sort listed data?

happy035
Explorer

I extracted some data from my set with this "stats count by failure_reason, dst | stats list(dst) as Target list(count) as "N of Target" by failure_reason "
The I got follow result set.

failure_reason dst [N of Target]
not a http reply line 107.23..199 27
108.168.
.6 5
110.75.***.240 9

I'd like to sort dst field using [N of Target]. Could you tell me how can I do that please?
Then one more question, I want to watch dstes over count such as over 100 count. How can I complete that?

Many Thanks

Tags (2)
0 Karma

happy035
Explorer

Hi Strive. It's correct. I want to extract destination list if count is greater than 100. But before it, I'd like to descending sort with N of Target.

0 Karma

strive
Influencer

Basically you need to sort dst based on Count in ascending order? Additionally you want to see only those dst(s) which have count greater than 100. Is that right?

0 Karma

PPape
Contributor

stats count by failure_reason, dst | stats list(dst) as Target list(count) as "N of Target" by failure_reason | sort 100 - "N of Target"

Should show you the top 100 results sorted by N of Target

can you give an example for your second question? I'm not sure if I understand it correct.

0 Karma

PPape
Contributor

Than try this:

stats count by failure_reason, dst | stats list(dst) as Target list(count) as "N of Target" by failure_reason | where "N of Target" >= 100 | sort 1000 - "N of Target"

0 Karma

happy035
Explorer

Thanks for comment PPape,
When I executed my script, I got a unsorted set in "N of target". I want descended sorting data with "N of Target" field. 100 means if count is greater than 100, I will include data set.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...