Splunk Dev

Comparing the 2 search results for a same search criteria and provide the data that do not match those 2 search results [Search done on different time]

Pravinraju
New Member

I need to compare the search results for my search criteria !

Example search criteria : host="iadtypweb*" | stats dc(session_id) as sessioncount, values(session_id) as sessionname
(I can specify the time in the Time Filter for the search)

The search criteria provides me the result of distinct session id and its value with respect to the host value specified. If this search is done on Saturday , and when I require to search this for Sunday , I need to find the occurrences of the event that do not match with Saturday results !

So it is possible to do this ? Do we have any built in functionalities to do this ?

If so provide me the sample query.

Tags (1)
0 Karma

renjith_nair
Legend

You can use sub searches for that http://docs.splunk.com/Documentation/Splunk/7.1.0/SearchTutorial/Useasubsearch

your current search|search NOT [search results from yesterday]

Also you could think about summary indexing where you store all the data you have found in last few days and exclude it in the current search ,

Reference : https://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/Usesummaryindexing

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...