<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does dedup command with sortby parameter in base searches produce duplicate results in Splunk 7.1.4? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415690#M119649</link>
    <description>&lt;P&gt;Please, take a look at this question about populating dropdown items &lt;A href="https://answers.splunk.com/answers/145911/how-to-populate-dropdown-input-with-ids-from-search.html"&gt;https://answers.splunk.com/answers/145911/how-to-populate-dropdown-input-with-ids-from-search.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Mar 2019 19:50:38 GMT</pubDate>
    <dc:creator>jnahuelperez35</dc:creator>
    <dc:date>2019-03-06T19:50:38Z</dc:date>
    <item>
      <title>Why does dedup command with sortby parameter in base searches produce duplicate results in Splunk 7.1.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415688#M119647</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;

&lt;P&gt;I've noticed a strange phenomenon with Splunk Enterprise 7.1.4 base searches and I wanted to see whether anyone else has noticed it too.  Here is what I've done:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Created accelerated data model&lt;/LI&gt;
&lt;LI&gt;Used accelerated data model in a base search&lt;/LI&gt;
&lt;LI&gt;Within the base search I use the dedup command with sortby parameter&lt;/LI&gt;
&lt;LI&gt;Created a panel based on the base search and used timechart command&lt;/LI&gt;
&lt;LI&gt;Made the panel a single with sparkline&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Now for the weird part.  The dashboard doubles the results in the panel!  If I open the panel in search through the magnifying glass icon it shows the correct, non-doubled value.  After further analysis I've found that there are two ways to get the panel working properly:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Remove the base search and replicate it to each panel, which is inefficient&lt;/LI&gt;
&lt;LI&gt;Remove the sortby parameter from the base search&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Is this a bug in Splunk?  Before anyone asks, no there are no duplicate events in the index.&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 10:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415688#M119647</guid>
      <dc:creator>andrewtrobec</dc:creator>
      <dc:date>2019-03-06T10:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why does dedup command with sortby parameter in base searches produce duplicate results in Splunk 7.1.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415689#M119648</link>
      <description>&lt;P&gt;Show some events and show the XML, so that we can try to reproduce it.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 15:59:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415689#M119648</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-06T15:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does dedup command with sortby parameter in base searches produce duplicate results in Splunk 7.1.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415690#M119649</link>
      <description>&lt;P&gt;Please, take a look at this question about populating dropdown items &lt;A href="https://answers.splunk.com/answers/145911/how-to-populate-dropdown-input-with-ids-from-search.html"&gt;https://answers.splunk.com/answers/145911/how-to-populate-dropdown-input-with-ids-from-search.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 19:50:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415690#M119649</guid>
      <dc:creator>jnahuelperez35</dc:creator>
      <dc:date>2019-03-06T19:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why does dedup command with sortby parameter in base searches produce duplicate results in Splunk 7.1.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415691#M119650</link>
      <description>&lt;P&gt;@woodcock I've tried to isolate and reproduce the issue in the search app but I cannot... I asked the question to see whether there was a known issue.  I wonder if it is permission related or whether there is some config file that causes this phenomenon.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 07:10:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415691#M119650</guid>
      <dc:creator>andrewtrobec</dc:creator>
      <dc:date>2019-03-07T07:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why does dedup command with sortby parameter in base searches produce duplicate results in Splunk 7.1.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415692#M119651</link>
      <description>&lt;P&gt;open a support case and ask Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 12:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-dedup-command-with-sortby-parameter-in-base-searches/m-p/415692#M119651</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-07T12:58:17Z</dc:date>
    </item>
  </channel>
</rss>

