Splunk Search

How to exclude equal values at the same field?

iabreu
New Member

Hello Splunkers,

I need a little help to exclude similar values at the same field in a search:

....| search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan

I need that all results that have similar values at field called "CaminhoCompleto" are not displayed at the result.

For example:

   Field 1------Caminhocompleto-------Field3---- 

1 123 ABC 098
2 324 ABC 987
3 234 CBA 678

In this case the line 1 and 2 would be excluded from the result, because the field Caminhocompleto have the value ABC appearing more than one time.

Best Regards,

Igor Abreu

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

If you want to filter those results after stats.

| search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan | evenstats count as tempcount by CaminhoCompleto | where tempcount=1

Before stats

 | search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | evenstats count as tempcount by CaminhoCompleto | where tempcount=1 | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan

View solution in original post

somesoni2
Revered Legend

The 2nd query should help.

0 Karma

iabreu
New Member

Yeah, exactly.

0 Karma

somesoni2
Revered Legend

Try something like this

If you want to filter those results after stats.

| search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan | evenstats count as tempcount by CaminhoCompleto | where tempcount=1

Before stats

 | search ComputadorNome="PCSD-FA5-TI11" | eval CaminhoCompleto=Caminho+ArquivoInfectado | evenstats count as tempcount by CaminhoCompleto | where tempcount=1 | stats count by ComputadorNome, TextoResultado, UsuarioLogado, CaminhoCompleto, TipoScan

somesoni2
Revered Legend

You want to exclude these entries (with more than 1 similar values) before the stats itself?

0 Karma

iabreu
New Member

No, I said "1" just to exemplify, I mean that if the field "CaminhoCompleto" have any equal values, all events will not be showed. For exemple:

Field 1------Caminhocompleto-------Field3----
123 ABC 098
324 ABC 987
234 CBA 678

In this case the line 1 and 2 would be excluded from the result, because the field Caminhocompleto have the value ABC appearing more than one time.

Regards.

0 Karma

strive
Influencer

Do you mean to say if the value for the field CaminhoCompleto is greater than 1 then you should exclude that event from the result

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...