Hey guys,
So I am trying to create a search that fetches the top 10 most active OOIDs (Organization ID Folder) by their activity of AOIDS (associate IDS) uploading documents into said folders. The idea is to get the number of AOIDS for each OOID.
For example, you have three companies:
Company A XYZ(OOID) has uploaded 300 documents, but only 20 AOIDS uploaded those documents
Company B ABC(OOID) has uploaded 200 documents, but 100 AOIDS uploaded those documents
The log of where I need to create the search out of is here:
Thanks for looking and please let me know if you have any questions!
Try this:
index = foo | stats dc(AOID) AS AOIDs by OOID | sort 10 - AOIDs
This judges "activity" not by raw activity but by the highest number of AOIDs that have any activity (which may not be correct); this judges by raw events:
index = foo | stats count dc(AOID) AS AOIDs by OOID | sort 10 - count
Try this:
index = foo | stats dc(AOID) AS AOIDs by OOID | sort 10 - AOIDs
This judges "activity" not by raw activity but by the highest number of AOIDs that have any activity (which may not be correct); this judges by raw events:
index = foo | stats count dc(AOID) AS AOIDs by OOID | sort 10 - count
You crushed the nail through the plywood, exactly what I wanted!
Try this untested search:
index = foo | top AOID by OOID | table OOID AOID
It is generating events but no statistics or a table
I've updated my answer.
I just need the number of AOIDS per OOID. The AOID name is not needed in this instace
You put a regex
tag on this question. Does that mean you don't have the OOID and AOID fields extracted?
Hi Rich and thanks for you're response,
I just checked and I actually do have them extracted, I just was not sure where to go from here