<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using &amp;quot; | reverse&amp;quot; in the command line returns duplicate results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65178#M16156</link>
    <description>&lt;P&gt;&lt;STRONG&gt;running a this query: splunk search "0e47015c-052f-4235-a25c-cbf3662371ee", returns this...&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;however, running this query: splunk search "0e47015c-052f-4235-a25c-cbf3662371ee | reverse", returns this...&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;why are duplicate results being returned? dedup doesn't help either.... thanks.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Oct 2010 21:09:45 GMT</pubDate>
    <dc:creator>rbbelen</dc:creator>
    <dc:date>2010-10-06T21:09:45Z</dc:date>
    <item>
      <title>Using " | reverse" in the command line returns duplicate results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65178#M16156</link>
      <description>&lt;P&gt;&lt;STRONG&gt;running a this query: splunk search "0e47015c-052f-4235-a25c-cbf3662371ee", returns this...&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;however, running this query: splunk search "0e47015c-052f-4235-a25c-cbf3662371ee | reverse", returns this...&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:506 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: CC not found&lt;/P&gt;

&lt;P&gt;[10/5/10 8:45:01:521 CDT] 0000001f CommonRules   E   0e47015c-052f-4235-a25c-cbf3662371ee -&amp;gt; Recipient with typeCode: BCC not found&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;why are duplicate results being returned? dedup doesn't help either.... thanks.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2010 21:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65178#M16156</guid>
      <dc:creator>rbbelen</dc:creator>
      <dc:date>2010-10-06T21:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Using " | reverse" in the command line returns duplicate results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65179#M16157</link>
      <description>&lt;P&gt;This is odd. What version are you running? You may want to &lt;A href="http://www.splunk.com/index.php/submit_issue" rel="nofollow"&gt;open a support ticket&lt;/A&gt; for this.&lt;/P&gt;

&lt;P&gt;You can work around this issue by using  &lt;CODE&gt;| sort - _time&lt;/CODE&gt; instead of &lt;CODE&gt;| reverse&lt;/CODE&gt; as such:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;0e47015c-052f-4235-a25c-cbf3662371ee | sort - _time
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 06 Oct 2010 22:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65179#M16157</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-10-06T22:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Using " | reverse" in the command line returns duplicate results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65180#M16158</link>
      <description>&lt;P&gt;This is a problem. We almost had a production issue due to this:&lt;/P&gt;

&lt;P&gt;Enterprise support
Case Number 50333
Windows 2003 R2
Splunk 4.1.5&lt;/P&gt;

&lt;P&gt;I didnt get much help from support - but thanks to this post, I was able to remove piping to reverse and find a way to get data across to our customer (which was part of a job which kicks off the Splunk command line, and then scrubs the data before presenting it to the customer system).&lt;/P&gt;

&lt;P&gt;BTW this might be a data driven thing - since it was a problem only the production system, while the CLI command ran fine on the QA system.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2010 06:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65180#M16158</guid>
      <dc:creator>sdevadas</dc:creator>
      <dc:date>2010-10-31T06:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Using " | reverse" in the command line returns duplicate results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65181#M16159</link>
      <description>&lt;P&gt;This is just a bug with "| reverse" from the command line because it tries to preview the output. You can disable preview with "-preview 0" from the command line.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2010 09:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65181#M16159</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2010-10-31T09:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Using " | reverse" in the command line returns duplicate results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65182#M16160</link>
      <description>&lt;P&gt;I figured out that it is just a bug in the reverse command - but it took me a couple of hours of my Friday evening after the team reported that 'Splunk is returning results incorrectly only in production'. After removing the reverse, the team was able to complete the release without having to introduce any code to remove duplicates at the last minute.&lt;/P&gt;

&lt;P&gt;The problem was that the bug did not show up in the CLI in the QA system or on the GUI in production, and did so only when we deployed the CLI based job to production, which was a problem since the team doing the release kept getting several records which the customer thought was some bug on our side. So my remark that it probably was a data-driven bug.&lt;/P&gt;

&lt;P&gt;I see now that it is known bug: &lt;A href="http://www.splunk.com/base/Documentation/latest/ReleaseNotes/Knownissues" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/ReleaseNotes/Knownissues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Will disable the preview output if we use reverse in the future.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Oct 2010 23:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-quot-reverse-quot-in-the-command-line-returns-duplicate/m-p/65182#M16160</guid>
      <dc:creator>sdevadas</dc:creator>
      <dc:date>2010-10-31T23:15:08Z</dc:date>
    </item>
  </channel>
</rss>

