dedup command syntax details
The required syntax is in bold.
- Syntax: <field> ["," <field>] ...
- Description: A list of comma-separated field names to remove duplicate values from. You must specify at least one field.
- Syntax: consecutive=<boolean>
- Description: If set to
true, removes only events with duplicate combinations of values that are consecutive.
- Default: false
- Syntax: <int>
- Description: The
dedupcommand retains multiple events for each combination when you specify <int>. The number for <int> must be greater than 0. If you do not specify a number, only the first occurring event is kept. All other duplicates are removed from the results.
- Default: 1
- Syntax: keepempty=<boolean>
- Description: If set to true, keeps every event where one or more of the specified fields is not present (null).
- Default: false. All events where any of the selected fields are null are dropped.
keepempty=trueargument keeps every event that does not have one or more of the fields in the <field-list>.
dedup command overview
dedup command usage
This documentation applies to the following versions of Splunk® Cloud Services: current