Splunk Dedup Command Tutorial

แชร์
ฝัง
  • เผยแพร่เมื่อ 3 พ.ย. 2024

ความคิดเห็น • 10

  • @ampleDee
    @ampleDee ปีที่แล้ว +1

    Amazing playlist ..you are doing good job keep it up :)

  • @giancarlocerza9159
    @giancarlocerza9159 11 หลายเดือนก่อน

    create channel, great work, great analyst!!

  • @skyscope8409
    @skyscope8409 4 หลายเดือนก่อน

    Amazing content!! Is dedup completely the same as uniq? Cheers.

    • @lamecreations_guides
      @lamecreations_guides  4 หลายเดือนก่อน

      They are slightly different.
      The uniq command removes duplicates if the whole event or row of a table are the same. It takes no fields or options as everything is checked. It is an ideal command if you have duplicate data.
      The dedup command looks only at the fields you tell it to. So if I say "| dedup host", it only looks at the host field and keeps the first from each host. You can specify multiple fields and has options like consecutive (only remove events with duplicate combinations of values that are in consecutive rows.) or keepempty (also keep events that do not have the requested field).

  • @manitechcreations163
    @manitechcreations163 หลายเดือนก่อน

    hi sir i want to be a soc analyst can u guide me

  • @AbhijeetPawar-xo2sb
    @AbhijeetPawar-xo2sb 7 หลายเดือนก่อน +1

    lol this video was specifically made to disrespect dedup command. Stats ate up dedup

    • @lamecreations_guides
      @lamecreations_guides  7 หลายเดือนก่อน

      disrespect might be a little strong, but I do encourage the use of the right tool for the right job :)