Hi all,
I have two searches here, which are nearly the same (5 Events more at one of them).
Is it somehow possible to Subtract the 289 events of the first search from the 294 other events of the second search?
Kind regards,
Katsche
Sadly there is not... but a new machine is already ordered. (12 CPU cores plus Hyperthreading instead of 2 cores witouht Hyperthreading and 96GB instead of 2GB RAM, that should work! xD)
ouch... I think Splunk doesn't provide a "| addRAM" command OOTB... 🙂
Ok, this is the answer, but I will have to figure out something else, because there is not enough RAM on my machine to run such a strong search...
Just checked the Search Reference Manual. Looks very promising. Let me run my search and I will get back to you. 🙂
I'd like to now the 5 events which are more.