I need to chart the sum of the values of a field by the value of another field over time (e.g. the sum of values of field A for all events that share the same value for field B). However, there is also a third field (field C), and if two events have same value for field C, I don't want them both included in the sum.
Generally, events with the same value for field C will be logged in Splunk at 2 minute intervals, but creating a timechart with a span of 2 minutes doesn't work perfectly because the time can be slightly more or less than 2 minutes. Is there a way to dedup events with the same field C within a certain time range? Or any other way to achieve this?
(your search)|bin span=2m _time|dedup _time,field_C
Can you do it?
I think that the condition is missing. Please present sample log.
(your search)|bin span=2m _time|dedup _time,field_C
Can you do it?
I think that the condition is missing. Please present sample log.
what does field_C supposed to do??
This worked perfectly! Thank you!
@eolg,
if it solved your questin, kindly accept the answer so other will know this solution worked for you