February 2017
Beginner to intermediate
962 pages
21h 26m
English
A quick way to get a summarized table based on fields is by using the top and rare commands. Run this search command:
SPL> index=main | top url
Notice that the result automatically grouped the URLs by count, calculated the percentage of each row against the whole data set, and sorted them by count in descending order. You can see a sample result in the following screenshot:

You may further tweak this search command by adding command options such as limit and showperc. Say, for example, you only want to see the top five URLs but you do not want to see the percent column. This is the command to achieve that:
SPL> index=main ...Read now
Unlock full access