Hi Team,
One of our customer reported that he was finding duplicate records in splunk ( duplicate files and duplicate data in files). We want to simulate the scenario in our lab. If someone can help to write SPL to find duplicate records.
Regards,
Alankrit
@Alankrit- Below is the search you can use. But just to clarify few points:
index=* sourcetype=* host=* | stats count by index, sourcetype, host, _raw | where count>1
I hope this helps!!! Kindly upvote if it does!!!