Splunk Search

Dedup Command information

ips_mandar
Builder

Hi,
Dedup command gives recent unique values based on fields mention. I want to know these recent values are identified based on _time or _indextime? I could not find it is mentioned anywhere.
Thanks,

0 Karma

HiroshiSatoh
Champion

If sortby is not specified, the default display order of Splunk will be applied, so it will be _time.

ips_mandar
Builder

I am asking this Because If I ingest same log(with few fields added) twice with same _time so does after dedup on fields present on both logs, it will display latest event which is indexed recently?

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...