Hi guys,
As I understand, dedup command will filter the complete set of results and remove any duplicate fields.
What if I want it to remove daily duplicates only? In other words, I would like to have duplicates, if their events happened on different days.
Is this possible?
Thanks,
Max
Dedup based on day as well:
... | eval mday = strftime(_time,"%d") | dedup yourfirstfield mday
Indeed it does the same. I'm confused regarding what behaviour you want. Could you show an example of desired vs undesired behaviour?
The mday does the same as "|timechart span=1d count" would. However it still removes all of the duplicates. (does not save duplicates if they happen on different days)