- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to get the difference of value between two tables?
aaa2324
Explorer
04-11-2022
12:05 AM
Hi Team,
I need to find difference between two tables and generate an alert when the diffence between Table B and Table A is greater than 3 and publish the diffence in table. Kindly help on this
Table A Table B
3234 3240
4234 4236
2345 2348
1345 1349
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
tshah-splunk

Splunk Employee
04-11-2022
05:10 AM
Hey @aaa2324 ,
Try renaming the columns in the table and remove the spaces in the column name and then you'll be able to calculate the difference easily. Your query should look something like below:
<<your_base_query>>
| rename "Table A" as Table_A "Table B" as Table_B
| eval diff=Table_B-Table_A
And then you can save this search as an alert and have the alert triggered if diff>3.
---
If you find the answer helpful, an upvote/karma is appreciated
If you find the answer helpful, an upvote/karma is appreciated
