Hi,
Dedup command gives recent unique values based on fields mention. I want to know these recent values are identified based on _time or _indextime? I could not find it is mentioned anywhere.
Thanks,
If sortby is not specified, the default display order of Splunk will be applied, so it will be _time.
I am asking this Because If I ingest same log(with few fields added) twice with same _time so does after dedup on fields present on both logs, it will display latest event which is indexed recently?