<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to compare two fields data from appendcols in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/614953#M213708</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I need support to know how I can get the non-existent values from the two fields obtained from the "appendcols" command output.&lt;/P&gt;&lt;P&gt;Example of Splunk output in table format below:&lt;/P&gt;&lt;P&gt;1st_Field&amp;nbsp; 2nd_Field&lt;/P&gt;&lt;P&gt;1111&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2222&lt;/P&gt;&lt;P&gt;empty&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3333&lt;/P&gt;&lt;P&gt;empty&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1111&lt;/P&gt;&lt;P&gt;I am able to get 1111 after using the lookup command but I want to get 2222 and 3333 only as those are not present in 1st Field.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 10:09:27 GMT</pubDate>
    <dc:creator>joomla</dc:creator>
    <dc:date>2022-09-28T10:09:27Z</dc:date>
    <item>
      <title>How to compare two fields data from appendcols</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/614953#M213708</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I need support to know how I can get the non-existent values from the two fields obtained from the "appendcols" command output.&lt;/P&gt;&lt;P&gt;Example of Splunk output in table format below:&lt;/P&gt;&lt;P&gt;1st_Field&amp;nbsp; 2nd_Field&lt;/P&gt;&lt;P&gt;1111&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2222&lt;/P&gt;&lt;P&gt;empty&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3333&lt;/P&gt;&lt;P&gt;empty&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1111&lt;/P&gt;&lt;P&gt;I am able to get 1111 after using the lookup command but I want to get 2222 and 3333 only as those are not present in 1st Field.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/614953#M213708</guid>
      <dc:creator>joomla</dc:creator>
      <dc:date>2022-09-28T10:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare two fields data from appendcols</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/614961#M213712</link>
      <description>&lt;P&gt;You could append the lookup (inputlookup) and then remove the events which have had successful lookups i.e. values in 1st_Field&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/614961#M213712</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-28T10:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to compare two fields data from appendcols</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/615021#M213734</link>
      <description>&lt;P&gt;Ok so I created the two different outlookup in main search and appendcols subseach and then used lookup command. This solved my purpose.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 15:20:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-compare-two-fields-data-from-appendcols/m-p/615021#M213734</guid>
      <dc:creator>joomla</dc:creator>
      <dc:date>2022-09-28T15:20:52Z</dc:date>
    </item>
  </channel>
</rss>

