Splunk Enterprise Security

How to remove a duplicate from a field result?

marceldera
Explorer

I am trying to remove duplicate from a field result:

index=tenable* sourcetype="*" severity_description="*" | table severity_description ip | stats count by severity_description

Results: 

Severity_description Count

Critical Severity    =       518

High Severity.        =.      46837

Medium Severity. =      7550

Low Severity.        =.       1460

Informative.           =.       275192

Inside each of severity_description row  there are duplicates i know that by running:

index=tenable* sourcetype="*" severity_description="Critical Severity" | table ip riskFactor | stats dc(ip) AS ip |rename ip as Critical | addcoltotals | stats sum(Critical) as Critical

Results: 

critical =128

I am trying to run the first search and remove the duplicates automatically from from each row

Labels (1)
0 Karma

somesoni2
Revered Legend

Give this a try

index=tenable* sourcetype="*" severity_description="*" | stats dc(ip) as count by severity_description
0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...