Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to search the last 90 days of BlueCoat logs for the top 100 websites?

$
0
0
This is the criteria I'm using: index=bcoat_logs sc_filter_result!=DENIED cs_host!="-" | stats count(cs_host) by cs_host | sort -count(cs_host) which lists all websites users are hitting, but this search takes forever to run. I was hoping to limit results to top 100 websites with highest hit counts in order to speed up the search. I'm a bit of a newb and could use some help.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>