Knowledge Management

help on comparison between 2 lookup

jip31
Motivator

hi

I use the search below in order to retrieve the fields host ,SITE and STATUS from a lookup and to compare them with the field host in another lookup
| inputlookup host.csv
| lookup lookup_cmdb_fo_all.csv HOSTNAME as host output SITE STATUS
| stats values(SITE) as SITE, values(STATUS) as STATUS by host

Now I need to display the host that exist in a lookup but not in another lookup
could you help me please??

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jip31,
do you want this in the same search or in another one?

if in another one it's easy:

| inputlookup host.csv NOT [ |inputlookup lookup_cmdb_fo_all.csv | rename HOSTNAME AS host | fields host ]
| ...

if instead you want this in the same search you have to modify your search in this way:

| inputlookup host.csv
| lookup lookup_cmdb_fo_all.csv HOSTNAME as host output SITE STATUS
| stats values(SITE) as SITE, values(STATUS) as STATUS by host
| eval Status=if(isnull(SITE),"Not present","Present")

Ciao.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi jip31,
do you want this in the same search or in another one?

if in another one it's easy:

| inputlookup host.csv NOT [ |inputlookup lookup_cmdb_fo_all.csv | rename HOSTNAME AS host | fields host ]
| ...

if instead you want this in the same search you have to modify your search in this way:

| inputlookup host.csv
| lookup lookup_cmdb_fo_all.csv HOSTNAME as host output SITE STATUS
| stats values(SITE) as SITE, values(STATUS) as STATUS by host
| eval Status=if(isnull(SITE),"Not present","Present")

Ciao.
Giuseppe

jip31
Motivator

hi guiseppe perfect thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...