Using top to show common field values

A very common question that may often arise is: "Which values are the most common?" When looking for errors, you are probably interested in figuring out what piece of code has the most errors. The top command provides a very simple way to answer this question.

Let's step through a few examples.

First, run a search for errors:

sourcetype="tm1" error

The preceding example searches for the word error in all source types starting with the character string "tm1*" (with the asterisk being the wildcard character).

In my data, it finds events containing the word error, a sample of which is listed in the following screenshot:

Since I happen to know that the data I am searching is made up of application log files ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.