Splunk Search

dedup maximum value

reverse
Contributor

Assuming there are 2 columns - Date & count and there are duplicates date.

How to dedup on Date and pick the maximum count value ?

2020-02-27  1522
2020-02-27  1680
2020-02-28  1639
2020-02-28  1639
2020-02-29  5
2020-02-29  5

Please guide.

Tags (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
your search
|sort 0 - count
| dedup Date

View solution in original post

to4kawa
Ultra Champion
your search
|sort 0 - count
| dedup Date

reverse
Contributor

thank you .. worked like a charm!!!

0 Karma

reverse
Contributor

@Vijeta - buddy .. you around ?

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...