Splunk Search
Highlighted

Split 'head' by a field?

Explorer

I want to limit a search with head, but do that split by a field: i.e. I want to limit my search to one result only ... per host, for example.

The caveat is, that the log entries are obviously not in order (so for example i may have 3 entries from host1, 2 entries from host2 and only one from host3) so doing something like head 3 for 3 hosts would not do it.

Tags (3)
Highlighted

Re: Split 'head' by a field?

Influencer

You can use the dedup command:

... | dedup host

View solution in original post

Highlighted

Re: Split 'head' by a field?

Explorer

exactly what I was looking for, thanks.

0 Karma