<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Elimination of duplicate logins over time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171399#M49087</link>
    <description>&lt;P&gt;Just took care of it &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/121885"&gt;@Jeff_Lightly_Sp&lt;/a&gt;lunk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:17:45 GMT</pubDate>
    <dc:creator>ppablo</dc:creator>
    <dc:date>2020-09-28T17:17:45Z</dc:date>
    <item>
      <title>Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171393#M49081</link>
      <description>&lt;P&gt;My problem is that in my data source, when a user logs on there can be a single entry or multiple entries. I need to eliminate the duplicates for each time interval but allow for future events by that User ID. I have tried dedup and distinct count. Does anyone have any suggestions?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* prdwfcs*/88 WFCSUID=UserID | stats count dc(WFCSUID)

index=* prdwfcs*/88 WFCSUID=UserID | dedup WFCSUID
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 05 Aug 2014 15:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171393#M49081</guid>
      <dc:creator>DonDandrea</dc:creator>
      <dc:date>2014-08-05T15:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171394#M49082</link>
      <description>&lt;P&gt;Does the multiple/duplicate login entries have same time stamp? Could you post some sample of duplicate entries?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 16:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171394#M49082</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-05T16:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171395#M49083</link>
      <description>&lt;P&gt;Yes, they have the same time stamp. I had not thought of it from that aspect. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 17:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171395#M49083</guid>
      <dc:creator>DonDandrea</dc:creator>
      <dc:date>2014-08-05T17:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171396#M49084</link>
      <description>&lt;P&gt;If the duplicates have same timestamp and other entries from that User Id are different, dedup of _time should do the job for you.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 17:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171396#M49084</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-05T17:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171397#M49085</link>
      <description>&lt;P&gt;Thank you somesoni2. dedup by _time did solve my issue.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 14:48:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171397#M49085</guid>
      <dc:creator>DonDandrea</dc:creator>
      <dc:date>2014-08-08T14:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171398#M49086</link>
      <description>&lt;P&gt;If possible, consider marking somesoni2's comment as an answer and accepting that answer. This will help others who may have similar issues in the future and it helps spread karma &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 15:35:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171398#M49086</guid>
      <dc:creator>Jeff_Lightly_Sp</dc:creator>
      <dc:date>2014-08-08T15:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Elimination of duplicate logins over time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171399#M49087</link>
      <description>&lt;P&gt;Just took care of it &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/121885"&gt;@Jeff_Lightly_Sp&lt;/a&gt;lunk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Elimination-of-duplicate-logins-over-time/m-p/171399#M49087</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2020-09-28T17:17:45Z</dc:date>
    </item>
  </channel>
</rss>

