<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Comparision in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552887#M156941</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this search compares the previous event data to the last event data based on your timerange&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| 
stats min(_indextime) as min_indextime max(_indextime) as max_indextime | convert ctime(min_indextime) ctime(max_indextime)&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 25 May 2021 07:05:15 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-05-25T07:05:15Z</dc:date>
    <item>
      <title>File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552875#M156934</link>
      <description>&lt;P&gt;How can we compare different versions of a file?&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552875#M156934</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-25T06:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552876#M156935</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you add more details?&lt;/P&gt;&lt;P&gt;this file is already indexed? where are stored the file? maybe it's better a versioning software?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:28:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552876#M156935</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-25T06:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552877#M156936</link>
      <description>&lt;P&gt;I have a file, say abc.csv, which I indexed once having events a b c , then i indexed it again after some days updating it, having events a b c d, again i indexed it at some point of time, having events a c and again then i uploaded it having events a b c.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My desired output&amp;nbsp;&amp;nbsp;&lt;BR /&gt;date 2- d&lt;/P&gt;&lt;P&gt;date 3- c&lt;/P&gt;&lt;P&gt;date 4- same&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552877#M156936</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-25T06:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552880#M156938</link>
      <description>&lt;P&gt;Try this search to check when is indexed an event&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=&amp;lt;your index&amp;gt;
| eventstats count by _raw
| where count=1
| table source _indextime _raw&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:41:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552880#M156938</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-25T06:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552882#M156939</link>
      <description>&lt;P&gt;This solution only compares the last and latest ones.. can u give something which compares the latest to all the previous ones.&amp;nbsp;&lt;BR /&gt;Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552882#M156939</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-25T06:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552887#M156941</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this search compares the previous event data to the last event data based on your timerange&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| 
stats min(_indextime) as min_indextime max(_indextime) as max_indextime | convert ctime(min_indextime) ctime(max_indextime)&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 25 May 2021 07:05:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552887#M156941</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-25T07:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552888#M156942</link>
      <description>&lt;P&gt;sir can u please elaborate the code , how to frame it properly&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 07:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552888#M156942</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-25T07:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552889#M156943</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please describe how you would like the&amp;nbsp; output search.&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 07:13:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552889#M156943</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-25T07:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552891#M156945</link>
      <description>&lt;P&gt;I have a file, say abc.csv, which I indexed once having events a b c , then i indexed it again after some days updating it, having events a b c d, again i indexed it at some point of time, having events a c and again then i uploaded it having events a b c.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My desired output&amp;nbsp;&amp;nbsp;&lt;BR /&gt;date 2- d&lt;/P&gt;&lt;P&gt;date 3- c&lt;/P&gt;&lt;P&gt;date 4- same&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 07:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552891#M156945</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-25T07:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552892#M156946</link>
      <description>&lt;LI-CODE lang="markup"&gt;index= &amp;lt;your index&amp;gt;
| stats values(_indextime) as indextime by _raw | convert ctime(indextime)&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 25 May 2021 07:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552892#M156946</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-25T07:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552920#M156955</link>
      <description>&lt;P&gt;This solution gives&amp;nbsp; _raw&amp;nbsp; present in all the versions. Not the event which is different.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akankshayadav_0-1621938511104.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14300i82A80FC90DF92DDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akankshayadav_0-1621938511104.png" alt="akankshayadav_0-1621938511104.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 10:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552920#M156955</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-05-25T10:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: File Comparision</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552937#M156958</link>
      <description>&lt;P&gt;ok now you can expand your indextime field&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index= &amp;lt;your index&amp;gt;
| stats values(_indextime) as indextime by _raw | convert ctime(indextime)
| mvexpand idextime 
| table idextime _raw&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 25 May 2021 13:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-Comparision/m-p/552937#M156958</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-25T13:15:41Z</dc:date>
    </item>
  </channel>
</rss>

