Splunk Search
Highlighted

Return daily unique field

Explorer

Hi guys,

As I understand, dedup command will filter the complete set of results and remove any duplicate fields.

What if I want it to remove daily duplicates only? In other words, I would like to have duplicates, if their events happened on different days.

Is this possible?

Thanks,
Max

Tags (2)
0 Karma
Highlighted

Re: Return daily unique field

Legend

Dedup based on day as well:

... | eval mday = strftime(_time,"%d") | dedup yourfirstfield mday
0 Karma
Highlighted

Re: Return daily unique field

Explorer

The mday does the same as "|timechart span=1d count" would. However it still removes all of the duplicates. (does not save duplicates if they happen on different days)

0 Karma
Highlighted

Re: Return daily unique field

Legend

Indeed it does the same. I'm confused regarding what behaviour you want. Could you show an example of desired vs undesired behaviour?

0 Karma