Dashboards & Visualizations

How to display only one row with duplicated columns

splunkkid
Path Finder

Hello,

I am trying to build Splunk Dashboard with my logs in splunk. The rows are like below.

 

[row 1]

{

 "id" : 123,
 "name" : "A",
 "sub_id" : 444,
 "count" : 25 

}

 

[row 2]

{

 "id" : 123,
 "name" : "A",
 "sub_id" : 445,
 "count" : 25 

}

 

As you can see, some of my results have the column with id value is same but sub_id is different.

I need to sum(count) only once if "id" is different, but the results came out as duplicated(not exactly twice, some results have same id with 3 or 4rows, So dividing by 2 is not a good solution.)

 

I want to build timechart with above data and made SPL like below.

host=[HOST] index=[INDEX] sourcetype=[SOURCETYPE] source=[SOURCE] | bucket span=1d _time | chart limit=0 sum(vm.count) as VM by _time

 

So, How could I sum count data if the id is same? Thank you,

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

So using the first vm.count for each vm.id in each bucket would give you the counts you need to sum?

host=[HOST] index=[INDEX] sourcetype=[SOURCETYPE] source=[SOURCE] 
| bucket span=1d _time 
| stats first(vm.count) as vm.count by _time vm.id
| chart limit=0 sum(vm.count) as VM by _time

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

When id is the same, are name and count also the same, only sub_id is different?

0 Karma

splunkkid
Path Finder

@ITWhisperer 

Yes, you're correct. I want to sum count only once by ID(But not grouping), and create timechart.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So using the first vm.count for each vm.id in each bucket would give you the counts you need to sum?

host=[HOST] index=[INDEX] sourcetype=[SOURCETYPE] source=[SOURCE] 
| bucket span=1d _time 
| stats first(vm.count) as vm.count by _time vm.id
| chart limit=0 sum(vm.count) as VM by _time

splunkkid
Path Finder

Thank you! That is correct!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...