If I understood the question correctly, you need a grouped search, e.g.
SELECT sourceip as "SRCIP", destinationip as "firstDSTIP", UNIQUECOUNT(destinationip) as (DSTIPcount), QIDNAME(qid) as "Event", COUNT() as "EventsCount"
FROM EVENTS
GROUP BY SRCIP
ORDER BY EventsCount DESC
LAST 2 HOURS

------------------------------
Dusan VIDOVIC
------------------------------
Original Message:
Sent: Thu June 26, 2025 11:59 AM
From: Umamaheshwara Manekar
Subject: Write AQl query to sort source IP address based on total event count
Hello Experts,
I am novice to writing AQL queries, would appreciate if you can provide me the AQL query, to sort source IP address based on total event count. I will build my other queries based on this.
Thank you very much in advance
Umamaheshwar
------------------------------
Umamaheshwara Manekar
------------------------------