HI, I am looking for something that is the 'opposite' of dedup; where the duplicate events are kept, and singular events are filtered out.
Any suggestions?
You can do something like below:
index=someindex | stats count by _raw
| where count>1
The above query will return events which are duplicated.