Splunk Search

Identify duplicate values in a field

azulueta
New Member

Hi,

I am new to Splunk and am looking for a search that is able to identify duplicate field values. We have an issue in Tenable that assets have duplicate asset IDs. My initial search is:

index=tenable sourcetype=tenable:io:assets
| stats count by hostnames, agent_uuid

Lists hostnames with ther unique ID on a table. Need to just show hostnames with the same agent_uuid.

I don't know if I need to export this and put it on a lookup table and then compare the agent_uuid values from there and just show the duplicates but I was hoping for a more straight forward search to do this. 🙂

Thank you.

0 Karma

yeahnah
Motivator

Hi @azulueta 

Try the following query

index=tenable sourcetype=tenable:io:assets
| stats count values(hostnames) BY agent_uuid
| where count > 1

Hope that helps

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...

Getting Started with Splunk Artificial Intelligence, Insights for Nonprofits, and ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...