Hi,
there is also a dedup for mvfields:
From the docs:
mvdedup(X)
This function takes a multi-valued field X and returns a multi-valued field with its duplicate values removed.
... | eval s=mvdedup(mvfield)
So maybe something like this will work?
mvcount(field)=1 | where b!=0 | eval lookupfield=logfield | lookup my_lookup_table lookupfield | table _time, field1, field2, field3, field4, field5, field6, lookuptablefield, field7, field8 | eval lookuptablefield=mvdedup(lookuptablefield)
I created a small run everywhere example:
| stats count | eval mvfield="a,a,a,b,b,b" | makemv mvfield delim="," | eval mvfield=mvdedup(mvfield) | fields - count
Greetings Tom
... View more