Is there an efficient way to mvdedup on all fields at once? Result is from transaction. Rather not convert to stats if don't have too.
The usual way to apply a function across multiple fields at once is to use foreach
. Does this give you what you're looking for?
your current search using transaction
| foreach *
[ | eval <<FIELD>>=mvdedup('<<FIELD>>') ]
The usual way to apply a function across multiple fields at once is to use foreach
. Does this give you what you're looking for?
your current search using transaction
| foreach *
[ | eval <<FIELD>>=mvdedup('<<FIELD>>') ]
Have a look at foreach command.
http://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Foreach
thank you!