Splunk Search

Having Splunk use a Unique Log Entry ID

cid_tangogroup
New Member

As part of logging events from our application we add a unique GUID to the event stream is there a way to tell spunk that this is a unique id and never import two events with the same GUID field value as they would be duplicates?

Thanks

Tags (3)
0 Karma

lguinn2
Legend

There is no way to tell Splunk that a field should not have duplicate values.

Get Updates on the Splunk Community!

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...

Splunk AppDynamics Agents Webinar Series

Mark your calendars! On June 24th at 12PM PST, we’re going live with the second session of our Splunk ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...