Splunk Search

Highest averages in each category

pveeramani
Explorer

(index=hosts) startminutesago="10" | stats avg(exectime) by host, pname

per host you can have many pnames

what I want is the top 5 with max averages in each host and thier pname

If I do a sort and head, its just going to give me the highest ones across all hosts and that is not what I want.

Tags (1)

Stephen_Sorkin
Splunk Employee
Splunk Employee

You should use the dedup command to get the top 5 per host:

(index=hosts) startminutesago="10" | stats avg(exectime) by host, pname | sort - host avg(exectime) | dedup 5 host

pveeramani
Explorer

Awesome, thanks.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...