Hello,
I would like to merge 2 lines which an ID is the unique Key.
Ex
Username Date ID
Max 1702
08/08/14 1702
and get just one line base on the unique ID
Username Date ID
Max 08/08/14 1702
Is it possible to do that?
I though that the command merge can help but do not success
Thanks for your help
Try something like this
your base search | table Username Date ID | stats first(*) as * by ID
I'm on Splunk 6.3 and there's a dedup command you can use in the search for this purpose.
your base search | dedup ID order by username desc
Is there a way apply this logic upon ingestion as opposed to search?
Try something like this
your base search | table Username Date ID | stats first(*) as * by ID
Just try but doesn't work (No results found). I see in the forum that maybe "transaction" command can help, i'll try
I have similar problem, I tried this approach and it works fine