Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I extract top values by a specific field and have them display along with corresponding fields in a table command?

$
0
0
index=* sourcetype=* host=* | search Event=176 | top limit=20 User| table Location, Event, User, Address, Time It displays the table but my columns with the fields **Location, User, Address and Time** appear to be empty. Any reason why?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>