so i have numerous field extractions in place. unfortunately due to the number of regex's there are some events that match two field extractions. the issue is that i have the same field name defined in both extractions.
this isn't a problem as splunk is nice enough to create a multivalue field for me automatically. it just so happens that the value of that field is the same for both entries!
is there a way i can reduce/normalise this so it doesn't show twice? (without reconstructing my regex's)
There really isn't an easy way globally.
In general, you might look at:
There really isn't an easy way globally.
In general, you might look at:
oh well... back to restructuring my regex's i guess... just a thought, when i do a top on such a field - would it double count? cheers,