<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Find the match in the column data and mark it as completed . in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654267#M226077</link>
    <description>&lt;P&gt;I tried the append , the final output display all the packages in "Server_Installed_Package.&amp;nbsp; I want only the package name as in "shouldBe"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE width="1525"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="160"&gt;CI_Name&lt;/TD&gt;&lt;TD width="162"&gt;installed&lt;/TD&gt;&lt;TD width="244"&gt;shouldBe&lt;/TD&gt;&lt;TD width="770"&gt;Server_Installed_Package&lt;/TD&gt;&lt;TD width="189"&gt;Vul_Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="160"&gt;server1&lt;/TD&gt;&lt;TD width="162"&gt;nss-3.44.0-7.el6_10&lt;/TD&gt;&lt;TD width="244"&gt;nss-3.44.0-13.el6_10&lt;/TD&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;TD width="189"&gt;Complete&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-devel-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-devel-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-freebl-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-freebl-3.44.0-6.el6_10.i686&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-freebl-devel-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-sysinit-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-tools-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-util-3.44.0-1.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-util-devel-3.44.0-1.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss_compat_ossl-0.9.6-2.el6_7&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Mon, 14 Aug 2023 11:36:48 GMT</pubDate>
    <dc:creator>Hema_Nithya</dc:creator>
    <dc:date>2023-08-14T11:36:48Z</dc:date>
    <item>
      <title>How to find the match in the column data and mark it as completed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654232#M226071</link>
      <description>&lt;P&gt;There are two searches with CI_Name as the common field . I have output and want compare the two columns installed and&amp;nbsp;Server_Installed_Package based on CI_Name as common , if both are common mark it as "Completed" in another column. If there is no match mark it as Not completed.&lt;/P&gt;
&lt;P&gt;first search output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="1394"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="457.641px" height="25px"&gt;CI_Name&lt;/TD&gt;
&lt;TD width="511.594px" height="25px"&gt;installed&lt;/TD&gt;
&lt;TD width="216.875px" height="25px"&gt;shouldBe&lt;/TD&gt;
&lt;TD width="206.891px" height="25px"&gt;match&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="457.641px" height="25px"&gt;Server1&lt;/TD&gt;
&lt;TD width="511.594px" height="25px"&gt;nss-3.44.0-7.el6_10&lt;/TD&gt;
&lt;TD width="216.875px" height="25px"&gt;nss-3.44.0-13.el6_10&lt;/TD&gt;
&lt;TD width="206.891px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="457.641px" height="114px"&gt;Server1&lt;/TD&gt;
&lt;TD width="511.594px" height="114px"&gt;
&lt;P&gt;nss-devel-3.44.0-7.el6_10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="216.875px" height="114px"&gt;nss-devel-3.44.0-13.el6_10&lt;/TD&gt;
&lt;TD width="206.891px" height="114px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="457.641px" height="25px"&gt;Server1&lt;/TD&gt;
&lt;TD width="511.594px" height="25px"&gt;nss-sysinit-3.44.0-7.el6_10&lt;/TD&gt;
&lt;TD width="216.875px" height="25px"&gt;nss-sysinit-3.44.0-13.el6_10&lt;/TD&gt;
&lt;TD width="206.891px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Second search output :&lt;/P&gt;
&lt;TABLE width="818"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="334"&gt;CI_Name&lt;/TD&gt;
&lt;TD width="484"&gt;Server_Installed_Package&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="334"&gt;Server1&lt;/TD&gt;
&lt;TD width="484"&gt;libgdata-0.6.4-2.el6.x86_64&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="334"&gt;Server1&lt;/TD&gt;
&lt;TD width="484"&gt;util-linux-ng-2.17.2-12.28.el6_9.2.x86_64&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="334"&gt;Server1&lt;/TD&gt;
&lt;TD width="484"&gt;rt73usb-firmware-1.8-7.el6.noarch&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="334"&gt;Server1&lt;/TD&gt;
&lt;TD width="484"&gt;sssd-1.13.3-60.el6_10.2.x86_64&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 17:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654232#M226071</guid>
      <dc:creator>Hema_Nithya</dc:creator>
      <dc:date>2023-08-14T17:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Find the match in the column data and mark it as completed .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654241#M226073</link>
      <description>&lt;P&gt;For the first search, you can check whether the columns match like this.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval match=if(installed=shouldBe,"Complete","Not complete")&lt;/LI-CODE&gt;&lt;P&gt;It is unclear what the second search is for.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 07:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654241#M226073</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-14T07:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Find the match in the column data and mark it as completed .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654244#M226074</link>
      <description>&lt;P&gt;I want to&amp;nbsp; match with second search field&amp;nbsp;&lt;SPAN&gt;Server_Installed_Package abd shouldbe&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval match=if(Server_Installed_Package=shouldBe,"Complete","Not complete")

Server_Installed_Package from second query 
shouldbe from first query 

Common field between two search query is CI_Name&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 07:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654244#M226074</guid>
      <dc:creator>Hema_Nithya</dc:creator>
      <dc:date>2023-08-14T07:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Find the match in the column data and mark it as completed .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654247#M226076</link>
      <description>&lt;LI-CODE lang="markup"&gt;&amp;lt;first search&amp;gt;
| append [&amp;lt;second search&amp;gt;]
| eventstats values(Server_Installed_Package) as Server_Installed_Package
| where isnotnull(installed)
| eval match=if(isnotnull(mvfind(Server_Installed_Package, shouldBe)), "Complete", "Not complete")&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 14 Aug 2023 08:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654247#M226076</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-14T08:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Find the match in the column data and mark it as completed .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654267#M226077</link>
      <description>&lt;P&gt;I tried the append , the final output display all the packages in "Server_Installed_Package.&amp;nbsp; I want only the package name as in "shouldBe"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE width="1525"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="160"&gt;CI_Name&lt;/TD&gt;&lt;TD width="162"&gt;installed&lt;/TD&gt;&lt;TD width="244"&gt;shouldBe&lt;/TD&gt;&lt;TD width="770"&gt;Server_Installed_Package&lt;/TD&gt;&lt;TD width="189"&gt;Vul_Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="160"&gt;server1&lt;/TD&gt;&lt;TD width="162"&gt;nss-3.44.0-7.el6_10&lt;/TD&gt;&lt;TD width="244"&gt;nss-3.44.0-13.el6_10&lt;/TD&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;TD width="189"&gt;Complete&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-devel-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-devel-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-freebl-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-freebl-3.44.0-6.el6_10.i686&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-softokn-freebl-devel-3.44.0-6.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-sysinit-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-tools-3.44.0-13.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-util-3.44.0-1.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss-util-devel-3.44.0-1.el6_10&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="770"&gt;&lt;P&gt;nss_compat_ossl-0.9.6-2.el6_7&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 14 Aug 2023 11:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654267#M226077</guid>
      <dc:creator>Hema_Nithya</dc:creator>
      <dc:date>2023-08-14T11:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Find the match in the column data and mark it as completed .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654269#M226078</link>
      <description>&lt;P&gt;Add this line&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| fields - Server_Installed_Package&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 14 Aug 2023 11:44:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-match-in-the-column-data-and-mark-it-as/m-p/654269#M226078</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-14T11:44:43Z</dc:date>
    </item>
  </channel>
</rss>

