I have two CSV files: vuln102018 vuln112018, both with the same fields.
I want to compare the files and create a table that shows the lines with the same results.
The fields "Host, Port, protocol, PID and CVE" are my key fields, and the search must be based in these fields to show the persistent results.
Can someone please help me?
Assuming you have both files indexed,
source=vuln_10_2018 OR source=vuln_11_2018 | stats dc(source) as source_count by Host Port protocol PID CVE | where source_count=2
I did with this query: