Dashboards & Visualizations

Find the difference between 2 tables.

anooshac
Communicator

Hi All,

How can i find the difference between 2 tables?.

index=abc task="task1"|dedup component1 |table component1
|append [index=abc task="task2" |dedup component2 |table component2]
|table component1 component2

these are the 2 tables. I want to show the extra data which are in component2 and not in component1.

How can i do it?

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Assuming component1 is a subset of component2 (which you seem to be implying)

| eval component=coalesce(component1, component2)
| stats count by component
| where count=1

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming component1 is a subset of component2 (which you seem to be implying)

| eval component=coalesce(component1, component2)
| stats count by component
| where count=1
0 Karma

anooshac
Communicator

Hi, @ITWhisperer , actually it is not subset. its just that im passing different token for taskand getting the 2nd table. In this case will coalesce will work?

index=abc task="$task1$"|dedup component1 |table component1
|append [index=abc task="$task2$" |dedup component2 |table component2]
|table component1 component2

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The coalesce will work it is just that if the count is 1 it could be that it only occurs in component1 or component2 and you would have to do something slightly different if you want to distinguish which set the component comes from

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...