Splunk Search

How can I remove duplicate from multiple columns at once?

marceldera
Explorer

Paranumber    Name

95929              Magnolia Jones Sr.

35716              Leslie Streich

99265              Magnolia Jones Sr.

152743            Kacey Cartwright

99265              Terence Deckow

95929              Magnolia Jones Sr.

131568            Dr. Ubaldo O'Kon

95929              Miss Maegan Adams

95929              Magnolia Jones Sr.

110231            Charley Casper

How can i remove duplicates only where the two columns natch.  for example,  95929              Magnolia Jones Sr. I want to remove duplicate of the entire row not by columns but by columns.  

Labels (2)
0 Karma

marceldera
Explorer

I figured it out

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @marceldera,

I don't know your solution, but it should be dedup for both your fields:

<your_search>
| dedup Paranumber Name
| sort Paranumber Name
| table Paranumber Name

Ciao.

Giuseppe

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@marceldera 

Kindly share your solution with other Splunkers and accept that solution to build community.

Happy Splunking

KV

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...