Splunk Search

Is there a "keepdup" command?

hirschel
New Member

HI, I am looking for something that is the 'opposite' of dedup; where the duplicate events are kept, and singular events are filtered out.

Any suggestions?

Labels (1)
Tags (2)
0 Karma

thambisetty
Super Champion

You can do something like below:

index=someindex | stats count by _raw

| where count>1

The above query will return events which are duplicated.

————————————
If this helps, give a like below.
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!