Splunk Search

Chart command.

sandeepmakkena
Contributor

index=aos_transaction

| chart count by payments, geo
| addtotals col=t
| sort -Total
| head 10

I want to display only top 10 payments with geo breakdown. when I use the above command my total is also showing in the bar chat.

Tags (2)
0 Karma

somesoni2
Revered Legend

Try this

index=aos_transaction 
| chart count by payments, geo
| addtotals
| sort -Total
| head 10

sandeepmakkena
Contributor

I alredy tried that but, the problem is when displaying as chart it is including total in the chart. I just want it to be used for sorting.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...