Hello Everyone,
I am running a search to find out the top 10 URLs visited by a single user:
index=ciscoasa user="" | top 10 URL
Is the search syntax fine? Because it is taking a lot of time to retrieve the results. Is there another way?
Thanks & Regards,
Binay Agarwal
Yes this is correct, just assuming you have a value in user="skoelpin"
I'm assuming your index is pretty massive since it has a lot of URLs in it. To decrease the time you could use event sampling, narrow down the time range, or put your data into a summary index which would massively increase the reporting speed.
Yes this is correct, just assuming you have a value in user="skoelpin"
I'm assuming your index is pretty massive since it has a lot of URLs in it. To decrease the time you could use event sampling, narrow down the time range, or put your data into a summary index which would massively increase the reporting speed.