I'm struggling to adapt this solution to my problem but I feel like it's the closest to what I'm looking for. I'm simply trying to get the top 10 src_ips in bytes of web usage, then the top 10 sites each of those src_ips goes to. My current solution is close but I can't seem to get to it just listing the top 10 sites for each IP, it seems to be doing the top sites overall and then spreading them over the src ips. index=proxy bytes>0 | fields src domain bytes |stats sum(bytes) AS totalbytes by domain,src |sort -totalbytes | head 50 |stats list(domain) as Domain, list(totalbytes) AS Total BY src | sort -Total I had to do the "head 50" because when I did head 10, i was only getting the top 10 domains in terms of bytes transferred and that was usually over just 3 or 4 IPs. By doing head 50, i was getting more domains to spread over more IPs but still not exactly what I wanted which would be 10 IPs and the top 10 sites for each IP.
... View more