How do I modify the following query to return the name of the FRUIT with the highest count:
index="myindex" URI="myuri" | stats count by FRUIT
Thanks,
Jonathan
Try this:
index="myindex" URI="myuri" | stats count by FRUIT|stats max(count) as max
You can do like this
index="myindex" URI="myuri" | top 1 FRUIT
This will give you name of top 1 FRUIT based on event count. You can adjust the number in top command to return more
Hi somesoni2,
That is perfect, thanks!
Now how could I modify your query to return the fruit name concatenated to the count in a single string like so:
apple:2013
Thanks,
Jonathan
A simple eval statement will do that
above search | eval FRUIT=FRUIT.":".count
Try this:
index="myindex" URI="myuri" | stats count by FRUIT|stats max(count) as max
That gives me the count, but I want to return the name of the fruit.
Thanks,
Jonathan
ok then try this it will give max count with name of fruit:
index="myindex" URI="myuri" | stats count by FRUIT|stats max(count) as max by FRUIT|head 1