HI,
I just want to ask if it's possible to have an incremental number in my output table in splunk search? Example:
Index=a dstip="*" | top limit=20 dstip
1 dstip1 100
2 dstip2 99
..
..
Originally the output has no # fields. Is possible to add that in my search command?
Thanks,
Try this
index=a dstip="*"
| top limit=20 dstip showcount=f
| eval counter=1
| accum counter as LineNumber
| fields - counter
| table LineNumber dstip percent
Hi Iguinn,
Thanks for your help. If I put the LineNumber on the on the last statement like this "table LineNumber dstip percent" no value on the LineNumber field is being displayed but when I search like this "table dstip percent LineNumber" it has a value.
Thanks you