Getting Data In

Is it possible to change/delete tags via search?

BMacher
Path Finder

Hi,

Can anyone tell me if it is possible to change and delete tags by Splunk search? Let me tell you why. I import data from a database. Each time a record is updated, I receive a new event in my index at the same time. Therefore, I am forced to sort all events before I can "dedup". My idea is the following:

When a new event occurs, I give it the tag "latest". When this event receives an update, I want to remove the tag "latest" of the older event and pass it to the new version. Therefore I don't have to sort the data anymore and can use "tag=latest" instead.

I know it isn't the right way to use tags because usually you would tag a field=value expression.

0 Karma
1 Solution

BMacher
Path Finder

I'm sorry to answer the question myself. But as far as I know, Dedup is set to "sortby - _indextime" by default. Because it always holds the most recent event.

That's why the solution is: | dedup fieldname sortby - _indextime

View solution in original post

0 Karma

BMacher
Path Finder

I'm sorry to answer the question myself. But as far as I know, Dedup is set to "sortby - _indextime" by default. Because it always holds the most recent event.

That's why the solution is: | dedup fieldname sortby - _indextime

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...