Splunk Search

Identify duplicate values in a field

azulueta
New Member

Hi,

I am new to Splunk and am looking for a search that is able to identify duplicate field values. We have an issue in Tenable that assets have duplicate asset IDs. My initial search is:

index=tenable sourcetype=tenable:io:assets
| stats count by hostnames, agent_uuid

Lists hostnames with ther unique ID on a table. Need to just show hostnames with the same agent_uuid.

I don't know if I need to export this and put it on a lookup table and then compare the agent_uuid values from there and just show the duplicates but I was hoping for a more straight forward search to do this. 🙂

Thank you.

0 Karma

yeahnah
Motivator

Hi @azulueta 

Try the following query

index=tenable sourcetype=tenable:io:assets
| stats count values(hostnames) BY agent_uuid
| where count > 1

Hope that helps

Tags (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...