How it works...

Let's break down the search piece by piece.

Search fragment

Description

index=main sourcetype=access_combined

You should now be familiar with this search from earlier recipes in this chapter.

| stats dc(clientip) AS Referals by referer_domain

Using the stats command, we apply the distinct count (dc) function to clientip to count the unique IP addresses by referer_domain and rename the generated count field to Referals.

| sort - Referals

Using the sort command, we sort by the number of referrals in the descending order.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.