Top 10 Countries and related Number of Users


1 comment

  • Avatar
    Ryan Johnson

    UPDATED: With the new fillmissing operator, you can use a quasi-subquery to achieve the same end.

    | parse "\"source_ip\": \"*\"" as c_ip
    | lookup country_name FROM geo://default ON ip=c_ip
    | timeslice 5m
    | count AS users BY _timeslice, country_name
    | filter country_name IN (sum(users) AS total_users_by_country BY country_name | sort total_users_by_country | limit 10 )
    | transpose row _timeslice column country_name
    Comment actions Permalink

Please sign in to leave a comment.