Where I work we are using Nessus to scan for vulnerabilities weekly. I'm in the process fo building a dashboard and making it all pretty for management. What I want to be able to do is compare the last two scans and get a difference between the total vulnerability of this weeks scan and the last one.
I don't have any input to provide and I couldn't find anything else on the Googles.
run a subsearch using
"search" | join type=inner [ |search "search" earliest=x latest=x]
Set the time picker as two weeks prior, the sub search would be the current time range. This should only show you events that were persistent between the two weeks
If you have got Splunk Enterprise security contains macro
make_previous_time_range(2) it takes two parameters earliest time and latest time as input.
for example, if you need to compare data today and yesterday you need to choose todays date and yesterday date will be automatically calculated using above mentioned macro.