Dashboards & Visualizations

How to display only one row with duplicated columns

splunkkid
Path Finder

Hello,

I am trying to build Splunk Dashboard with my logs in splunk. The rows are like below.

 

[row 1]

{

 "id" : 123,
 "name" : "A",
 "sub_id" : 444,
 "count" : 25 

}

 

[row 2]

{

 "id" : 123,
 "name" : "A",
 "sub_id" : 445,
 "count" : 25 

}

 

As you can see, some of my results have the column with id value is same but sub_id is different.

I need to sum(count) only once if "id" is different, but the results came out as duplicated(not exactly twice, some results have same id with 3 or 4rows, So dividing by 2 is not a good solution.)

 

I want to build timechart with above data and made SPL like below.

host=[HOST] index=[INDEX] sourcetype=[SOURCETYPE] source=[SOURCE] | bucket span=1d _time | chart limit=0 sum(vm.count) as VM by _time

 

So, How could I sum count data if the id is same? Thank you,

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

So using the first vm.count for each vm.id in each bucket would give you the counts you need to sum?

host=[HOST] index=[INDEX] sourcetype=[SOURCETYPE] source=[SOURCE] 
| bucket span=1d _time 
| stats first(vm.count) as vm.count by _time vm.id
| chart limit=0 sum(vm.count) as VM by _time

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

When id is the same, are name and count also the same, only sub_id is different?

0 Karma

splunkkid
Path Finder

@ITWhisperer 

Yes, you're correct. I want to sum count only once by ID(But not grouping), and create timechart.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So using the first vm.count for each vm.id in each bucket would give you the counts you need to sum?

host=[HOST] index=[INDEX] sourcetype=[SOURCETYPE] source=[SOURCE] 
| bucket span=1d _time 
| stats first(vm.count) as vm.count by _time vm.id
| chart limit=0 sum(vm.count) as VM by _time

splunkkid
Path Finder

Thank you! That is correct!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...