Splunk Search

Outputnew: How do I compare two Fields in two Lookup tables?

russell120
Communicator

Hello,

I need help finding out how I can display field values of one lookup that are not present in the same-named field as another lookup.

Ex: lookup1.csv has the below data.
Field: colors
red
orange
yellow

Ex: lookup2.csv has the below data.
Field: colors
orange
red
green
blue

The results should display yellow because yellow is a value within the colors field of lookup1.csv , but is not a value in the colors field of lookup2.csv.

Thanks.

Tags (2)
0 Karma
1 Solution

russell120
Communicator

|inputlookup lookup1.csv
|lookup lookup2.csv colors OUTPUTNEW colors as Missing_Colors
|where isnull(Missing_Colors)

Ah, this did the trick.

View solution in original post

0 Karma

russell120
Communicator

|inputlookup lookup1.csv
|lookup lookup2.csv colors OUTPUTNEW colors as Missing_Colors
|where isnull(Missing_Colors)

Ah, this did the trick.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...