Hello, I am new to splunk. I need to get the top 5 products sold for each day, for the last 7 days. The products could be different each day, as shown in the example below.
Day (X-Axis)
Top 5 Products (Y-Axis)
1
2
3
4
5
1
P1
PA
P4
AC
ZX
2
P2
PB
P5
AR
P1
3
P3
PC
PA
P5
AC
4
P4
P1
P1
P4
AR
5
P5
PD
AB
AX
AB
Is there a way to get it done? I tired the following but it gives me the same 5 products for all days and puts everything else in "OTHER" bucket: [my search] | table _time, Product | timechart count(Product) byProduct WHERE max in top5
... View more