Hi Umamaheshwar,
Welcome to the world of AQL! If you're looking to sort source IP addresses based on the total event count, here's a basic AQL query you can start with:
aql
- Copy
- Edit
- SELECT sourceip, COUNT(*) as event_count
- FROM events
- GROUP BY sourceip
- ORDER BY event_count DESC
This query will:
- Count the number of events for each sourceip
- Group them accordingly
- Sort the result in descending order based on event count
You can now use this as a foundation and add more filters or conditions as needed.
Let me know if you need help customizing it further!
Best,
RHJ
------------------------------
Rh Jaffery
------------------------------
Original Message:
Sent: Thu June 26, 2025 11:59 AM
From: Umamaheshwara Manekar
Subject: Write AQl query to sort source IP address based on total event count
Hello Experts,
I am novice to writing AQL queries, would appreciate if you can provide me the AQL query, to sort source IP address based on total event count. I will build my other queries based on this.
Thank you very much in advance
Umamaheshwar
------------------------------
Umamaheshwara Manekar
------------------------------