Please see picture below. I inserted dedup for job_duration, but it was not showing in the search result. I only need one result to do visualisation.
Asked
Active
Viewed 1,358 times
0
2 Answers
0
It looks like job_min is a multi-value field, which are not supported by dedup. Try ... | eval job_min=mvdedup(duration) | ....
RichG
- 143
- 6
0
If job_min is in a multivalue field, you should mvexpand first
And, instead of dedup, try using stats
Like this:
| mvexpand job_min
| stats count by job_min
| fields - count
warren
- 10,322
