Splunk Search

suppressing adjacent events with duplicate field values

Justin_Grant
Contributor

I have a log which often has redundant events, where "redundant" is defined as 2+ events, on subsequent lines, where each redundant event has the same value for a particular field (e.g. "ID").

How can I suppress the second and subsequent events so only the first event in a set shows up in my search results?

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You can pipe the events through | dedup consecutive=true fieldname

sourcetype=mydupeylog | dedup consecutive=true mydupeyfield

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

You can pipe the events through | dedup consecutive=true fieldname

sourcetype=mydupeylog | dedup consecutive=true mydupeyfield

Justin_Grant
Contributor

Cool! BTW, the docs for the dedup command are here: http://www.splunk.com/base/Documentation/latest/SearchReference/Dedup

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...