To filter for only IP addresses that appear more than five times in the search results for index=games, you can use a combination of the stats and where commands. The stats command counts the occurrences of each IP address and assigns the count to IP_count. The where command then filters the results to include only those IP addresses with a count greater than five.
Here is how the complete search would look:
index=games | stats count as IP_count by IP | where IP_count > 5
[References:, Splunk Docs: stats command, Splunk Docs: where command, Splunk Answers: Filtering results using stats and where commands, , , , , , ]
Submit