Let's break down the search piece by piece.
Search fragment |
Description |
index=main sourcetype=access_combined |
You should now be familiar with this search from earlier recipes in this chapter. |
| stats dc(clientip) AS Referals by referer_domain |
Using the stats command, we apply the distinct count (dc) function to clientip to count the unique IP addresses by referer_domain and rename the generated count field to Referals. |
| sort - Referals |
Using the sort command, we sort by the number of referrals in the descending order. |