Splunk Search

Can you help me with Dedup events in a data model?

iKate
Builder

Hi everyone

How do I leave just unique events by specified field in an accelerated data model?

My base search looks like:

index=main source=transactions tx_type=purchase | `registration_time` | `type_user` 

And I'm trying to add child dataset with just one constraint: dedup transaction_id

But it didn't work.

Duplicated transaction_id cannot be deleted from original source 'cause it's a feature of some transactions... But, in data model, we just need one occurrence of it, e.g. to sum revenue.

With this query we get a greater result than we actually have because of counting several times transactions with the same transaction_id. How can we get correct result?

Thanks in advance!

| tstats sum(transactions.price) AS Revenue from datamodel=transact.transactions where (nodename = transactions) groupby _time span=1month
| rename transactions.* as *
| timechart span=1month first(Revenue) as revenue
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...