I have this search to show top 5 values:
search... | fields ALARM | stats count by ALARM | sort limit=5 -count
Result for above is shown in a dashboard as a pie chart. How do I search for the rest of ALARM to show in a separate pie chart? Values for ALARM vary depending on time range.
Sorry if duplicate, did not find a similar question.
Try like this
search... | fields ALARM | top limit=5 useother=t showperc=f ALARM
Updated
Try this. This will exclude top 5 and give the rest (streamstats will assign rank/serial no to sorted list and then we filter top 5)
search...| fields ALARM | stats count by ALARM | sort 0 -count | streamstats count as rank | where rank>5 | fields - rank
search...
| fields ALARM
| stats count by ALARM
| search NOT [search... | fields ALARM | stats count by ALARM | sort limit=5 -count | table ALARM]
this works if my time range is set to past 3 days where there are less than 1M events, however, when I tried past 30 days with 10M events, it pulled up all ALARM values
sorry, this actually works, forgot to add the table ALARM at the end. however, this takes twice the time as compared to somesoni2's - thank you!
That makes sense - it's doing twice the work!
Wouldn't have posted it at all if somesoni2's second answer had been posted yet.
Try like this
search... | fields ALARM | top limit=5 useother=t showperc=f ALARM
Updated
Try this. This will exclude top 5 and give the rest (streamstats will assign rank/serial no to sorted list and then we filter top 5)
search...| fields ALARM | stats count by ALARM | sort 0 -count | streamstats count as rank | where rank>5 | fields - rank
this pulled up the top 5 and "other" values for ALARM
I didn't fully read I guess. Try the updated answer.
thank you, this works.