Dedup in Kibana search


(Rohit Jawle) #1

In splunk, there is a command called dedup, followed by a field name. How do you do this in elk?


(Mark Walkom) #2

What are you trying to do?


(Rohit Jawle) #3

I'm trying to get it so that for every value in a field (for example, for every individual ip address), it only shows the first result.


(Mark Walkom) #4

Then look at doing an aggregation of some sort on the IP field.


(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.