Splunk Search

dedup maximum value

reverse
Contributor

Assuming there are 2 columns - Date & count and there are duplicates date.

How to dedup on Date and pick the maximum count value ?

2020-02-27  1522
2020-02-27  1680
2020-02-28  1639
2020-02-28  1639
2020-02-29  5
2020-02-29  5

Please guide.

Tags (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
your search
|sort 0 - count
| dedup Date

View solution in original post

to4kawa
Ultra Champion
your search
|sort 0 - count
| dedup Date

reverse
Contributor

thank you .. worked like a charm!!!

0 Karma

reverse
Contributor

@Vijeta - buddy .. you around ?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...