Splunk Search

Removing consecutive events with identical 'name' field but different timestamp in a transaction

merethhe
Engager

I run this search:

... | dedup userId name dt | transaction mvlist=t userId maxpause=900s | where mvindex(id, -1) == "1152921526082717650" | table name, dt

Which creates transactions based on userId that ends with the specified page id, and removes events that are equal in name and timestamp for each user. It gives me a result for instance like this:

A, 19:00:00
B, 19:00:30
C, 19:01:00
C, 19:01:35
B, 19:02:00

What I want to do now, is remove all events that follow an event with the exact same name, that is I want to remove the second "C" event. The problem is, I do NOT want to remove the second "B" event, even though it already occured in the transaction. This means that I can not use dedup on the (name, userId) combination.

Any suggestions?

0 Karma

somesoni2
Revered Legend

Give this a try

... | dedup userId name dt | transaction mvlist=t userId maxpause=900s | where mvindex(id, -1) == "1152921526082717650" | table name, dt | streamstats current=f window=1 first(name) as prevName | where name != prevName
0 Karma

merethhe
Engager

It did not work. 'prevName' seems to be set as the name of the first event from the previous transaction.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...