I am getting so many results for a single search keyword.how do i make a unique single result for that search keyword.
for example if i am search like this ..
sourcetype="A" xyz
i am getting differnt results that contain "xyz" ..due to duplicate source files in my index.
i need to display only the unique event of the search parameter .. how can i do tat ?? thanx...
base search... |dedup source
The problem is that xyz
is just a free text search, as opposed to some_parameter=xyz
, which is more precise.
Always try to minimize the the time span over which you're searching.
If you have duplicates, try using ... | dedup _raw
/k