Splunk Search

Split 'head' by a field?

Explorer

I want to limit a search with head, but do that split by a field: i.e. I want to limit my search to one result only ... per host, for example.

The caveat is, that the log entries are obviously not in order (so for example i may have 3 entries from host1, 2 entries from host2 and only one from host3) so doing something like head 3 for 3 hosts would not do it.

Tags (3)
1 Solution

Influencer

You can use the dedup command:

... | dedup host

View solution in original post

Influencer

You can use the dedup command:

... | dedup host

View solution in original post

Explorer

exactly what I was looking for, thanks.

0 Karma