Splunk Search

How to remove the row if the column is same?

Wind
New Member

Such as when I using the following search:
sourcetype="xyz" status=* |stats dc(ID) by ID status |sort by ID
I will get the following table
ID status dc(ID)
12345 true 1
12345 false 1
92345 true 1
82345 false 1

Can you tell me how to get the following table?
ID status dc(ID)
12345 true 1
92345 true 1
82345 false 1

That means remove the above second row(When ID is duplicated, remove the row about the "false" column)

Thanks advance for your help.

Tags (3)
0 Karma

neelamssantosh
Contributor

dedup is a expensive command.
so, instead use only ID after by clause section i.e,

sourcetype="xyz" status=* |stats values(status) dc(ID) by ID |sort by ID

0 Karma

Wind
New Member

I have fixed by myself as followings:)
sourcetype="xyz" status=* |stats dc(ID) by ID status |sort ID| sort - status | dedup 1 ID

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...