I've got proxy logs and I want to show the top 5 urls and for that the count of distinct users who tried to access it.
I tried the following search command
index=proxy
| eval dc_user=[search* stats dc(user) by url| return $dc_user]
| top dest_host limit=5
| table dest_host dc_user
How can I get this work?
I also wanted to add the count of the url and the percentage.
Thank you in advance.
Does this do what you need?
index=proxy
| eventstats dc(user) as unique_users by url
| top url
| sort 5 - count
| table url, unique_users, count, percent
Give this a try
index=proxy
| stats dc(user) as UniqUsers count by dest_host
| sort 5 -count