<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Comparision in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552494#M156824</link>
    <description>&lt;P&gt;Files are indexed through inputs.cong .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Files differs as.. example file1 indexed today has 1event&amp;nbsp; ZC_01;11;13;30 and when updated and indexed it has 2 events&amp;nbsp;ZC_01;11;13;30&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;ZC_01;11;13;29&lt;/P&gt;&lt;P&gt;i have to display the result as...&amp;nbsp;&amp;nbsp;&amp;nbsp;ZC_01;11;13;29 this is the newly added data in the updated file1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 May 2021 05:50:50 GMT</pubDate>
    <dc:creator>akankshayadav</dc:creator>
    <dc:date>2021-05-21T05:50:50Z</dc:date>
    <item>
      <title>File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552488#M156821</link>
      <description>&lt;P&gt;I have a file which is being indexed(say today) and then again indexed after updating(say tomorrow). I have to compare the events of the two versions and display the event(s) which is present in the&amp;nbsp; new one but not in old or vice versa. Can any help?&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 04:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552488#M156821</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-21T04:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552489#M156822</link>
      <description>&lt;P&gt;How is the file indexed? How do the events differ from day to day? How many events per file when indexed? What else can you say about the indexing process?&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 05:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552489#M156822</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-21T05:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552494#M156824</link>
      <description>&lt;P&gt;Files are indexed through inputs.cong .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Files differs as.. example file1 indexed today has 1event&amp;nbsp; ZC_01;11;13;30 and when updated and indexed it has 2 events&amp;nbsp;ZC_01;11;13;30&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;ZC_01;11;13;29&lt;/P&gt;&lt;P&gt;i have to display the result as...&amp;nbsp;&amp;nbsp;&amp;nbsp;ZC_01;11;13;29 this is the newly added data in the updated file1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 05:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552494#M156824</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-21T05:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552501#M156828</link>
      <description>&lt;P&gt;Do the events from the two different days have different timestamps? Do events from the first indexing also appear in the second indexing (just with different timestamps)?&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 06:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552501#M156828</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-21T06:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552504#M156829</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akankshayadav_0-1621578250200.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14254iBAA153AB25ABAE2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akankshayadav_0-1621578250200.png" alt="akankshayadav_0-1621578250200.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akankshayadav_1-1621578348703.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14255iCF5B3846B470ADB3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akankshayadav_1-1621578348703.png" alt="akankshayadav_1-1621578348703.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This image can help you understand the scenario.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 06:26:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552504#M156829</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-21T06:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552507#M156831</link>
      <description>&lt;P&gt;How about something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search 1
| append [search 2]
| eventstats count by _raw
| where count=1&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 21 May 2021 06:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552507#M156831</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-21T06:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552508#M156832</link>
      <description>&lt;P&gt;Actually sir, i am a very beginner. Can you&amp;nbsp; elaborate the query in an clear way. The above one didn't work. What should i write in place of search 1 and 2?&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 06:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552508#M156832</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-21T06:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552514#M156834</link>
      <description>&lt;P&gt;You might not need two searches if both times the file is indexed they go into the same index&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="compindex"
| eventstats count by _raw
| where count=1&lt;/LI-CODE&gt;&lt;P&gt;The problem with defining your question with non-specific or fabricated examples is that the answers are often just as vague and it takes longer to resolve, but this is the price we pay for anonymisation&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 07:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552514#M156834</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-21T07:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552515#M156835</link>
      <description>&lt;P&gt;i did this one and got the resutl. thank u sir. and one more help.. how to display it as a table with columns&amp;nbsp;&lt;/P&gt;&lt;P&gt;source&amp;nbsp; time(when file was indexed latest)&amp;nbsp; OnlyThe NewData&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 07:07:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552515#M156835</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-21T07:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552517#M156837</link>
      <description>&lt;LI-CODE lang="markup"&gt;index="compindex"
| eventstats count by _raw
| where count=1
| table source _indextime _raw&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 21 May 2021 07:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552517#M156837</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-21T07:16:10Z</dc:date>
    </item>
  </channel>
</rss>

