0

Please see picture below. I inserted dedup for job_duration, but it was not showing in the search result. I only need one result to do visualisation.

screenshot

2 Answers2

0

It looks like job_min is a multi-value field, which are not supported by dedup. Try ... | eval job_min=mvdedup(duration) | ....

RichG
  • 143
  • 6
0

If job_min is in a multivalue field, you should mvexpand first

And, instead of dedup, try using stats

Like this:

| mvexpand job_min
| stats count by job_min
| fields - count
warren
  • 10,322