Splunk Search

How can I remove duplicate from multiple columns at once?

marceldera
Explorer

Paranumber    Name

95929              Magnolia Jones Sr.

35716              Leslie Streich

99265              Magnolia Jones Sr.

152743            Kacey Cartwright

99265              Terence Deckow

95929              Magnolia Jones Sr.

131568            Dr. Ubaldo O'Kon

95929              Miss Maegan Adams

95929              Magnolia Jones Sr.

110231            Charley Casper

How can i remove duplicates only where the two columns natch.  for example,  95929              Magnolia Jones Sr. I want to remove duplicate of the entire row not by columns but by columns.  

Labels (2)
0 Karma

marceldera
Explorer

I figured it out

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @marceldera,

I don't know your solution, but it should be dedup for both your fields:

<your_search>
| dedup Paranumber Name
| sort Paranumber Name
| table Paranumber Name

Ciao.

Giuseppe

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@marceldera 

Kindly share your solution with other Splunkers and accept that solution to build community.

Happy Splunking

KV

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...