Hi ,
I am trying to update a multivalued field in a KV store. So let's say there are 3 values in the field:
A,B,A. During the update, I would want to remove A from the field. However, I want to remove only one instance of A and not all the instances.
Can anyone help me out with how to implement this logic in Splunk?
Try this..
.... | streamstats count | mvexpand mvfieldinkvstore | dedup count mvfieldinkvstore | mvcombine mvfieldinkvstore | fields - count
Have look at the eval-mvdedup
command