HI ,
Need some help on removing the duplicates from table. Am querying the accounts which uses the plain port connection as LDAP for particular timestamp.
My query :
index=*** host=host1 OR host=host2 source=logpath | transaction startswith=protocol=LDAP | search BIND REQ NOT "protocol=LDAPS" NOT | dedup "uid"
If i uses the above query in a table am getting two values in a row and again for other timestamp the same value got repeated even though am using dedup . I have tried consecutive=true. In the UID column am seeing duplicates still.
results came like this:
timestamp | uid |
2023-12-12T05:44:23.000-05:00 | abc xyz |
2023-12-12T05:45:20.000-05:00 | abc efg 123 |
2023-12-12T05:45:20.000-05:00 | xyz 456 efg |
I need each value in single row and no duplicates should displayed. Help will much appreciated!!!
Try something like this
| stats count by timestamp, uid