<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I compare fields between two events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12968#M1100</link>
    <description>&lt;P&gt;That does it, but I'd like to know the difference in time between the two dates as well in, say, hours.&lt;/P&gt;</description>
    <pubDate>Thu, 06 May 2010 00:03:59 GMT</pubDate>
    <dc:creator>hacktastic</dc:creator>
    <dc:date>2010-05-06T00:03:59Z</dc:date>
    <item>
      <title>How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12964#M1096</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm Splunking some report data that is in CSV format, which may or may not matter in the context of this question. I've got Splunk set up to index the CSV data line-by-line and I've set props.conf and transforms.conf to properly assign fields to the CSV data, so that's all done. I need to do a comparison of the dates between two events that are coming from two different hosts but share common fields. For example:&lt;/P&gt;

&lt;P&gt;Log1 from HostA: "field1","field2","field3","dateA"&lt;/P&gt;

&lt;P&gt;Log2 from HostB: "field1","field2","field3","dateB"&lt;/P&gt;

&lt;P&gt;In plain English: "Match up the lines from HostA and HostB where field1, field2 and field3 are identical, then compare the dates. If the dates do not match, report this back."&lt;/P&gt;

&lt;P&gt;I'm drawing a blank on how to do this. Your help is appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2010 23:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12964#M1096</guid>
      <dc:creator>hacktastic</dc:creator>
      <dc:date>2010-05-05T23:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12965#M1097</link>
      <description>&lt;P&gt;Not entirely sure I understand, but how about:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | stats distinct_count(datefield) as diff_dates by field1,field2,field3 | where diff_dates &amp;gt; 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 05 May 2010 23:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12965#M1097</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-05T23:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12966#M1098</link>
      <description>&lt;P&gt;Here are two approaches, not sure which will work best for you:&lt;/P&gt;

&lt;P&gt;Search 1:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;&lt;CODE&gt;your search | transaction fields="field1,field2,field3" | search duration&amp;gt;0&lt;/CODE&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Search 2:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;&lt;CODE&gt;your search | stats dc(_time) as times, values(_time) as time_values, by field1, field2, field3 | search times&amp;gt;1 | convert ctime(time_values)&lt;/CODE&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;It's not clear from your question if &lt;CODE&gt;dateA&lt;/CODE&gt; and &lt;CODE&gt;dateB&lt;/CODE&gt; represent two different dates or two different field names.  In the searches above, I'm assuming that your actually talking about the timestamp of your event, which is accessible in the &lt;CODE&gt;_time&lt;/CODE&gt; field.  &lt;/P&gt;

&lt;P&gt;If you do have two field names, then perhaps this could work for you:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;&lt;CODE&gt;your search | transaction fields="field1,field2,field3" | where dateA!=dateB&lt;/CODE&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;EM&gt;Note:  You have to use &lt;CODE&gt;where&lt;/CODE&gt; when you are comparing the value of two different fields.  You can use &lt;CODE&gt;search&lt;/CODE&gt; if you are comparing against a constant value.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2010 23:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12966#M1098</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-05-05T23:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12967#M1099</link>
      <description>&lt;P&gt;DateA and DateB are part of the results, not time stamps. I need to know if these dates differ.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 00:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12967#M1099</guid>
      <dc:creator>hacktastic</dc:creator>
      <dc:date>2010-05-06T00:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12968#M1100</link>
      <description>&lt;P&gt;That does it, but I'd like to know the difference in time between the two dates as well in, say, hours.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 00:03:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12968#M1100</guid>
      <dc:creator>hacktastic</dc:creator>
      <dc:date>2010-05-06T00:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12969#M1101</link>
      <description>&lt;P&gt;... | stats max(datefield) as d1, min(datefield) as d2 by field1,field2,field3 | eval ddiff = d1-d2 | where ddiff &amp;lt;&amp;gt; 0&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 03:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12969#M1101</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-06T03:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare fields between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12970#M1102</link>
      <description>&lt;P&gt;Awesome. Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 04:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-fields-between-two-events/m-p/12970#M1102</guid>
      <dc:creator>hacktastic</dc:creator>
      <dc:date>2010-05-06T04:14:50Z</dc:date>
    </item>
  </channel>
</rss>

