I have some data (cleaned syslog) that we are using the Top function to see top Destination IP addresses in some log data
From the results shown, how can you get it to display data from normal additional queries that I run on this data like | top Src_Address or | top Dst_Port..... wether displayed via a link or inline ...
I am guessing its a subquery but cant see how you define this
thanks
Splunk has a top
command to do this:
... | top Src_Address