Splunk Search

list "top" command question

dikaye
Path Finder

Hi, My mail server logs display recipient info like that:

Feb 14 16:04:25 224.67.24.175 Feb 14 16:04:25 mail_logs: Info: MID 1563086 ICID 1105367 RID 0 To: <user.1@abc.com>

How can I list the top 10 recipients by search command?

Thanks.

Tags (1)
0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

You need to remove the : from To in your search.

Also... If you haven't trained Splunk to recognize your To field, you'll want to run the IFX wizard to extract the field. Here's a link on how to do this:

http://www.splunk.com/base/Documentation/4.1.7/User/InteractiveFieldExtractionExample

dikaye
Path Finder

I create it as the savedsearches.conf like that:

[Top recipients - pie chart]
action.email.sendresults = 0
dispatch.ttl = 3600
displayview = report_builder_display
relation = None
request.ui_dispatch_view = report_builder_display
search = index=all_test host=224.67.24.175 | top To: limit=10
vsid = *:fwkfzepj

But, when I run this saved search, it has not thing display.

Why?

0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

Assuming you have your fields extracted properly:

... | top limit=10 To
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...