<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to compare 2 field values and exclude matching results from the final output / count in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474487#M192481</link>
    <description>&lt;P&gt;Below is my search output  for the SPL  i am running.&lt;/P&gt;

&lt;P&gt;`&lt;BR /&gt;
&lt;STRONG&gt;db_1&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
oracle_test&lt;BR /&gt;&lt;BR /&gt;
db2_bio&lt;BR /&gt;&lt;BR /&gt;
oracle_890&lt;BR /&gt;&lt;BR /&gt;
n88888&lt;BR /&gt;&lt;BR /&gt;
n7777                   &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;server_2&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
n87896&lt;BR /&gt;
bg8768&lt;BR /&gt;
j987653&lt;BR /&gt;
n88888&lt;BR /&gt;&lt;BR /&gt;
n7777&lt;CODE&gt;&lt;/CODE&gt;                 &lt;/P&gt;

&lt;P&gt;How do i exclude the field records which are identical between 2 fields  like in this case  -- (n88888 &amp;amp; n7777)&lt;/P&gt;

&lt;P&gt;I tried using there where clause /Search  , but without any success  ..&lt;/P&gt;

&lt;P&gt;SPL used to display fields records which are not identical  ---&lt;/P&gt;

&lt;P&gt;|splunk command | where db_1 != server_2    ( Not wokring )&lt;/P&gt;

&lt;P&gt;|splunk Command | fields db_1,server_2 | search db_1 !=server_2  ( Not working )&lt;/P&gt;

&lt;P&gt;Any clue/help will be appreciated  ?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:15:05 GMT</pubDate>
    <dc:creator>promukh</dc:creator>
    <dc:date>2020-09-30T04:15:05Z</dc:date>
    <item>
      <title>How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474487#M192481</link>
      <description>&lt;P&gt;Below is my search output  for the SPL  i am running.&lt;/P&gt;

&lt;P&gt;`&lt;BR /&gt;
&lt;STRONG&gt;db_1&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
oracle_test&lt;BR /&gt;&lt;BR /&gt;
db2_bio&lt;BR /&gt;&lt;BR /&gt;
oracle_890&lt;BR /&gt;&lt;BR /&gt;
n88888&lt;BR /&gt;&lt;BR /&gt;
n7777                   &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;server_2&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
n87896&lt;BR /&gt;
bg8768&lt;BR /&gt;
j987653&lt;BR /&gt;
n88888&lt;BR /&gt;&lt;BR /&gt;
n7777&lt;CODE&gt;&lt;/CODE&gt;                 &lt;/P&gt;

&lt;P&gt;How do i exclude the field records which are identical between 2 fields  like in this case  -- (n88888 &amp;amp; n7777)&lt;/P&gt;

&lt;P&gt;I tried using there where clause /Search  , but without any success  ..&lt;/P&gt;

&lt;P&gt;SPL used to display fields records which are not identical  ---&lt;/P&gt;

&lt;P&gt;|splunk command | where db_1 != server_2    ( Not wokring )&lt;/P&gt;

&lt;P&gt;|splunk Command | fields db_1,server_2 | search db_1 !=server_2  ( Not working )&lt;/P&gt;

&lt;P&gt;Any clue/help will be appreciated  ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474487#M192481</guid>
      <dc:creator>promukh</dc:creator>
      <dc:date>2020-09-30T04:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474488#M192482</link>
      <description>&lt;P&gt;what's field name, &lt;CODE&gt;n88888&lt;/CODE&gt; &amp;amp; &lt;CODE&gt;n7777&lt;/CODE&gt;?&lt;BR /&gt;
and&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;oracle_test db2_bio oracle_890 n88888 n7777
n87896 bg8768 j987653 n88888 n7777
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;your result is this?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 22:38:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474488#M192482</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-19T22:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474489#M192483</link>
      <description>&lt;P&gt;field names are  -- source1.db_1 &amp;amp; source1.server_2&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474489#M192483</guid>
      <dc:creator>promukh</dc:creator>
      <dc:date>2020-09-30T04:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474490#M192484</link>
      <description>&lt;P&gt;yes ..correct .. i want to exclude the matching records from both fields&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 22:53:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474490#M192484</guid>
      <dc:creator>promukh</dc:creator>
      <dc:date>2020-02-19T22:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474491#M192485</link>
      <description>&lt;P&gt;what's your query?&lt;BR /&gt;
server and db is another&lt;BR /&gt;
host?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 23:22:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474491#M192485</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-19T23:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474492#M192486</link>
      <description>&lt;P&gt;db_1:&lt;BR /&gt;
source1.db_1 n88888&lt;BR /&gt;
source1.server_2 n7777&lt;/P&gt;

&lt;P&gt;server_2:&lt;BR /&gt;
source1.db_1 n88888&lt;BR /&gt;
source1.server_2 n7777&lt;BR /&gt;
this 2 results is exclude. right?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474492#M192486</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-09-30T04:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474493#M192487</link>
      <description>&lt;P&gt;yes want to exclude those 2 values in the final output&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 23:48:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474493#M192487</guid>
      <dc:creator>promukh</dc:creator>
      <dc:date>2020-02-19T23:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare 2 field values and exclude matching results from the final output / count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474494#M192488</link>
      <description>&lt;P&gt;ok , I was able to resolve using a single quote around the field name along with a where clause.&lt;/P&gt;

&lt;P&gt;|splunk command | where 'db_1'!='server_2'&lt;/P&gt;

&lt;P&gt;Found the below input in the splunk documentation which helped ..&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkInvestigate/Current/SearchReference/WhereCommandOverview" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkInvestigate/Current/SearchReference/WhereCommandOverview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;where 'host-name'="buttercup"   If the expression references a field name that contains characters other than a-z, A-Z, 0-9, or the underscore ( _ ) character, the field name must be surrounded by single quotation marks.&lt;/P&gt;

&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:15:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-2-field-values-and-exclude-matching-results-from/m-p/474494#M192488</guid>
      <dc:creator>promukh</dc:creator>
      <dc:date>2020-09-30T04:15:14Z</dc:date>
    </item>
  </channel>
</rss>

