Using top to show common field values

A very common question that may often arise is, "What values are most common?" When looking for errors, you are probably interested in figuring out what piece of code has the most errors. The top command provides a very simple way to answer this question.

Let's step through a few examples.

First, run a search for errors:

sourcetype="tm1*" error

The preceding example searches for the word error in all sourcetypes starting with the character string "tm1*" (with the asterisk being the wildcard character).

In my data, we find events containing the word error, a sample of which is listed in the following screenshot:

Using top to show common field values

Get Implementing Splunk - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.