Dashboards & Visualizations

Find the difference between 2 tables.

anooshac
Communicator

Hi All,

How can i find the difference between 2 tables?.

index=abc task="task1"|dedup component1 |table component1
|append [index=abc task="task2" |dedup component2 |table component2]
|table component1 component2

these are the 2 tables. I want to show the extra data which are in component2 and not in component1.

How can i do it?

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Assuming component1 is a subset of component2 (which you seem to be implying)

| eval component=coalesce(component1, component2)
| stats count by component
| where count=1

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming component1 is a subset of component2 (which you seem to be implying)

| eval component=coalesce(component1, component2)
| stats count by component
| where count=1
0 Karma

anooshac
Communicator

Hi, @ITWhisperer , actually it is not subset. its just that im passing different token for taskand getting the 2nd table. In this case will coalesce will work?

index=abc task="$task1$"|dedup component1 |table component1
|append [index=abc task="$task2$" |dedup component2 |table component2]
|table component1 component2

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The coalesce will work it is just that if the count is 1 it could be that it only occurs in component1 or component2 and you would have to do something slightly different if you want to distinguish which set the component comes from

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...