Getting Data In

Is it possible to change/delete tags via search?

BMacher
Path Finder

Hi,

Can anyone tell me if it is possible to change and delete tags by Splunk search? Let me tell you why. I import data from a database. Each time a record is updated, I receive a new event in my index at the same time. Therefore, I am forced to sort all events before I can "dedup". My idea is the following:

When a new event occurs, I give it the tag "latest". When this event receives an update, I want to remove the tag "latest" of the older event and pass it to the new version. Therefore I don't have to sort the data anymore and can use "tag=latest" instead.

I know it isn't the right way to use tags because usually you would tag a field=value expression.

0 Karma
1 Solution

BMacher
Path Finder

I'm sorry to answer the question myself. But as far as I know, Dedup is set to "sortby - _indextime" by default. Because it always holds the most recent event.

That's why the solution is: | dedup fieldname sortby - _indextime

View solution in original post

0 Karma

BMacher
Path Finder

I'm sorry to answer the question myself. But as far as I know, Dedup is set to "sortby - _indextime" by default. Because it always holds the most recent event.

That's why the solution is: | dedup fieldname sortby - _indextime

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...