Splunk Search

dedup maximum value

Contributor

Assuming there are 2 columns - Date & count and there are duplicates date.

How to dedup on Date and pick the maximum count value ?

2020-02-27  1522
2020-02-27  1680
2020-02-28  1639
2020-02-28  1639
2020-02-29  5
2020-02-29  5

Please guide.

Tags (1)
0 Karma
1 Solution

SplunkTrust
SplunkTrust
your search
|sort 0 - count
| dedup Date

View solution in original post

SplunkTrust
SplunkTrust
your search
|sort 0 - count
| dedup Date

View solution in original post

Contributor

thank you .. worked like a charm!!!

0 Karma

Contributor

@Vijeta - buddy .. you around ?

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!