Monitoring Splunk

How to get the difference of value between two tables?

aaa2324
Explorer

Hi Team,

I need to find difference between two tables and generate an alert when the diffence between Table B and Table A is greater than 3 and publish the diffence in table. Kindly help on this

Table A       Table B   

3234          3240

4234           4236

2345           2348

1345           1349

Labels (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @aaa2324 ,

Try renaming the columns in the table and remove the spaces in the column name and then you'll be able to calculate the difference easily. Your query should look something like below:

 

<<your_base_query>>
| rename "Table A" as Table_A "Table B" as Table_B
| eval diff=Table_B-Table_A

 

And then you can save this search as an alert and have the alert triggered if diff>3.

---
If you find the answer helpful, an upvote/karma is appreciated
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...