For the following search, which command would further filter for only IP addresses present more than five times?
To filter for only IP addresses that appear more than five times in the search results for index=games, you can use a combination of the stats and where commands. The stats command counts the occurrences of each IP address and assigns the count to IP_count. The where command then filters the results to include only those IP addresses with a count greater than five.
Here is how the complete search would look:
index=games | stats count as IP_count by IP | where IP_count > 5
Splunk Docs: stats command
Splunk Docs: where command
Splunk Answers: Filtering results using stats and where commands
Lashawna
3 months agoCarrol
3 months agoMeghann
3 months agoErick
4 months agoGrover
4 months agoWhitney
4 months agoJerry
4 months agoCorrinne
4 months agoAlethea
5 months agoDevora
5 months agoMitsue
5 months agoCathrine
5 months agoSharika
5 months agoStefany
1 year agoMaricela
1 year agoRessie
1 year agoOna
1 year agoJordan
1 year agoDoretha
1 year agoCathern
1 year agoDoretha
1 year agoRichelle
1 year agoPeter
1 year agoVivan
1 year agoTommy
1 year agoRaymon
1 year agoReena
1 year agoLeah
1 year agoGeraldo
1 year ago