HI , i am new to splunk i need to create a report that has rest calls which has mulitple path parameters , so it was showing the multiple uris to make a status count on that
for example:
/t1/email/ksjdf@gmail.com
/t1/email/ksjdf@gmail.com/f1/12345
/t1/email/ytft@gmail.com
/t1/email/ytft@gmail.com/f1/123456
result should be like this :
/t1/email/
/t1/email/XXXX/f1/XXXX
how to remove the duplicates herer , i am not which command to use?..
Hi 12onetwo,
given you have a field called path
or uri
you can use dedup
on this field
base search goes here | dedup uri | stats count by uri
see the doce for more details http://docs.splunk.com/Documentation/Splunk/6.3.0/SearchReference/Dedup
Hope this helps ...
cheers, MuS