Splunk Search

Is there a "keepdup" command?

HI, I am looking for something that is the 'opposite' of dedup; where the duplicate events are kept, and singular events are filtered out.

Any suggestions?

You can do something like below:

index=someindex | stats count by _raw

| where count>1

The above query will return events which are duplicated.

