Splunk Search

How to reverse results of dedup in the same command ?

welcominh
New Member

Im having an issue when trying to dedup some values. Here are the logs of servers states im having in Splunk, from the latest to the oldest

1 - UP
2 - UP
3 - UP
4 - UP
5 - DOWN
6 - DOWN
7 - DOWN
8 - DOWN
9 - DOWN

When trying to dedup with dedup state consecutive=true i get the following results :

1 - UP
5 - DOWN

Is there any way to get instead the following results ?

4 - UP
5 - DOWN

That is to say the oldest result for UP values, and the latest for DOWN values.

Thanks in advance !

0 Karma

somesoni2
Revered Legend

You can do this

your base search giving latest to earliest listing of states
| reverse | dedup state consecutive=true

OR

your base search giving latest to earliest listing of states
| dedup state consecutive=true sortby +_time
0 Karma

welcominh
New Member

This does not give me the expected result...It is exactly the same problem but reversed...

9 - DOWN
4 - UP
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...