Which one would be faster or better in general:
1. | dedup fieldA fieldB --> I would assume that Splunk does a concatenation in the background
2. | eval fieldAB = fieldA.fieldB | dedup fieldAB
↧