Splunk Search

How to edit my current search to remove duplicate rows from the resulting table?

Path Finder


I am using a table which shows up duplicates. Example shown below.
Is there a way to write a search which removes duplicates from the table?
I am pasting the search here for reference.

*index= source="dbmon-tail://db" Status = "2" TrackName = "Ab-Initio"|convert timeformat="%Y-%m-%d %H:%M:%S" ctime(time) AS UpdateDateTime |table UpdateDateTime, TrackName,ApplicationName,ComponentName,StatusDesc,ltserrordescription,Comments

This above search returns the two rows below, of which I need only the latest one based on date.

alt text

0 Karma


I think it would be helpful if you could expand on what fields determine the unique rows you want to keep. Right now that seems unclear.

0 Karma


Look into the dedup command.

If this reply helps you, an upvote would be appreciated.
0 Karma