Monitoring Splunk

How to get the difference of value between two tables?

aaa2324
Explorer

Hi Team,

I need to find difference between two tables and generate an alert when the diffence between Table B and Table A is greater than 3 and publish the diffence in table. Kindly help on this

Table A       Table B   

3234          3240

4234           4236

2345           2348

1345           1349

Labels (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @aaa2324 ,

Try renaming the columns in the table and remove the spaces in the column name and then you'll be able to calculate the difference easily. Your query should look something like below:

 

<<your_base_query>>
| rename "Table A" as Table_A "Table B" as Table_B
| eval diff=Table_B-Table_A

 

And then you can save this search as an alert and have the alert triggered if diff>3.

---
If you find the answer helpful, an upvote/karma is appreciated
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...