Top values
top_valuesRank Graylog field values by exact count and percentage to identify dominant sources, status codes, or user agents in a time range.
Instructions
Top N values of a field with exact counts and percentages.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| field | Yes | Field to group by, e.g. source, http_status, user_agent | |
| limit | No | Number of values | |
| query | No | Lucene query, '*' for everything | * |
| range | No | Relative range ending now (or at to_time): '15m', '2h', '1d', '1h30m' | 1h |
| streams | No | Stream titles or ids to search in; all streams when omitted | |
| to_time | No | Absolute end, same formats as from_time; default now | |
| instance | No | Graylog instance (environment) from list_instances, e.g. 'staging' or 'prod'; the default instance when omitted | |
| from_time | No | Absolute start: ISO 8601 or 'YYYY-MM-DD HH:MM' in the instance timezone; overrides range |