Hi,
I am new to Splunk and am looking for a search that is able to identify duplicate field values. We have an issue in Tenable that assets have duplicate asset IDs. My initial search is:
index=tenable sourcetype=tenable:io:assets
| stats count by hostnames, agent_uuid
Lists hostnames with ther unique ID on a table. Need to just show hostnames with the same agent_uuid.
I don't know if I need to export this and put it on a lookup table and then compare the agent_uuid values from there and just show the duplicates but I was hoping for a more straight forward search to do this. 🙂
Thank you.