<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Compare Two Different Fields in a Multisearch in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Compare-Two-Different-Fields-in-a-Multisearch/m-p/412662#M118942</link>
    <description>&lt;P&gt;I am trying to obtain a list of ids for orders that were abandoned/forgotten and never received a submit. I have a multisearch that finds a list of all ids when they are created and another search that finds the ids when they are submitted. I would like to find all of the values that appear only in the first list. Is there a command to do this without comparing two lookups? Here is my search:&lt;BR /&gt;
&lt;CODE&gt;| multisearch &lt;BR /&gt;
    [ search create call" | extract id ] &lt;BR /&gt;
    [ search submit call | extract id ] &lt;BR /&gt;
| table created_cart_id submitted_cart_id&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2019 17:11:45 GMT</pubDate>
    <dc:creator>dsitek</dc:creator>
    <dc:date>2019-07-24T17:11:45Z</dc:date>
    <item>
      <title>Compare Two Different Fields in a Multisearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Compare-Two-Different-Fields-in-a-Multisearch/m-p/412662#M118942</link>
      <description>&lt;P&gt;I am trying to obtain a list of ids for orders that were abandoned/forgotten and never received a submit. I have a multisearch that finds a list of all ids when they are created and another search that finds the ids when they are submitted. I would like to find all of the values that appear only in the first list. Is there a command to do this without comparing two lookups? Here is my search:&lt;BR /&gt;
&lt;CODE&gt;| multisearch &lt;BR /&gt;
    [ search create call" | extract id ] &lt;BR /&gt;
    [ search submit call | extract id ] &lt;BR /&gt;
| table created_cart_id submitted_cart_id&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 17:11:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Compare-Two-Different-Fields-in-a-Multisearch/m-p/412662#M118942</guid>
      <dc:creator>dsitek</dc:creator>
      <dc:date>2019-07-24T17:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Compare Two Different Fields in a Multisearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Compare-Two-Different-Fields-in-a-Multisearch/m-p/412663#M118943</link>
      <description>&lt;P&gt;I just posted this but the most obvious solution hit me in the face. After the &lt;CODE&gt;table&lt;/CODE&gt; command, rename both fields to be the same, count them, and select only ones that appear once.&lt;BR /&gt;
&lt;CODE&gt;rename created_cart_id AS cart_id, submitted_cart_idea AS cart_id | stats count by cart_id | where count=1&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 17:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Compare-Two-Different-Fields-in-a-Multisearch/m-p/412663#M118943</guid>
      <dc:creator>dsitek</dc:creator>
      <dc:date>2019-07-24T17:17:58Z</dc:date>
    </item>
  </channel>
</rss>

