Hello Splunkers,
I need a little help to exclude similar values at the same field in a search:
....| search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan
I need that all results that have similar values at field called "CaminhoCompleto" are not displayed at the result.
For example:
   Field 1------Caminhocompleto-------Field3---- 
1       123              ABC                098 
2       324              ABC                987 
3       234              CBA                678
In this case the line 1 and 2 would be excluded from the result, because the field Caminhocompleto have the value ABC appearing more than one time.
Best Regards,
Igor Abreu
 
					
				
		
Try something like this
If you want to filter those results after stats.
| search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan | evenstats count as tempcount by CaminhoCompleto | where tempcount=1
Before stats
 | search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | evenstats count as tempcount by CaminhoCompleto | where tempcount=1 | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan
 
					
				
		
The 2nd query should help.
Yeah, exactly.
 
					
				
		
Try something like this
If you want to filter those results after stats.
| search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan | evenstats count as tempcount by CaminhoCompleto | where tempcount=1
Before stats
 | search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | evenstats count as tempcount by CaminhoCompleto | where tempcount=1 | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan
 
					
				
		
You want to exclude these entries (with more than 1 similar values) before the stats itself?
No, I said "1" just to exemplify, I mean that if the field "CaminhoCompleto" have any equal values, all events will not be showed. For exemple:
Field 1------Caminhocompleto-------Field3----
  123             ABC                098
  324             ABC                987
  234             CBA                678
In this case the line 1 and 2 would be excluded from the result, because the field Caminhocompleto have the value ABC appearing more than one time.
Regards.
 
					
				
		
Do you mean to say if the value for the field CaminhoCompleto is greater than 1 then you should exclude that event from the result
