I am new and learning splunk, I have a 2 events like below with same event type. name='name1', user='abc', type='type1', other-fields : latest event name='name1', user='abc1', type='type1', other-fields : past event name='name2', user='def', type='type2', other-fields I want to dedup based on user field, but the dedup value changes but all other fields remain same. In this case I want to match fields name & type between first 2 events and pick up the latest one. My final filtered events should be: name='xyz', user='abc', type='new', other-fields name='name2', user='def', type='type2', other-fields Any suggestions?
... View more