Remove duplicate entries.
How do i remove duplicate entries from a query? In Splunk you have command (
In Sumo we recommend:
...| count BY fieldName
| fields - _count
You can check out other Splunk migration recommendations here:
Please sign in to leave a comment.