Splunk Search

How can I remove duplicate from multiple columns at once?

marceldera
Explorer

Paranumber    Name

95929              Magnolia Jones Sr.

35716              Leslie Streich

99265              Magnolia Jones Sr.

152743            Kacey Cartwright

99265              Terence Deckow

95929              Magnolia Jones Sr.

131568            Dr. Ubaldo O'Kon

95929              Miss Maegan Adams

95929              Magnolia Jones Sr.

110231            Charley Casper

How can i remove duplicates only where the two columns natch.  for example,  95929              Magnolia Jones Sr. I want to remove duplicate of the entire row not by columns but by columns.  

Labels (2)
0 Karma

marceldera
Explorer

I figured it out

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @marceldera,

I don't know your solution, but it should be dedup for both your fields:

<your_search>
| dedup Paranumber Name
| sort Paranumber Name
| table Paranumber Name

Ciao.

Giuseppe

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@marceldera 

Kindly share your solution with other Splunkers and accept that solution to build community.

Happy Splunking

KV

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...