I too having same kind of issue . I have tried with your solution , but still I can see duplicate values . please help @ITWhisperer
I have no idea what SPL you used to create that output since you didn't share it. Having said that, given that you apparently have three occurrences of the same string, perhaps your base data is at fault, or perhaps you have trailing spaces?
I got the solution .
mvexpand doesn't work because the field is not a multi-value field. It's a single-value field with embedded newlines. Tried using the split function to break up the field then mvexpand and it works
This field contains multiple duplicate values I guess.
You can remove it like this:
index=graphsecurityalert | mvexpand title | dedup title | table title
Check to see which events contain those multivalues:
index=graphsecurityalert | eval c=mvcount(title) | table c
| eval title=mvdedup(title)
| stats count by title
| fields - count