Monitoring Splunk

How to get the difference of value between two tables?

aaa2324
Explorer

Hi Team,

I need to find difference between two tables and generate an alert when the diffence between Table B and Table A is greater than 3 and publish the diffence in table. Kindly help on this

Table A       Table B   

3234          3240

4234           4236

2345           2348

1345           1349

Labels (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @aaa2324 ,

Try renaming the columns in the table and remove the spaces in the column name and then you'll be able to calculate the difference easily. Your query should look something like below:

 

<<your_base_query>>
| rename "Table A" as Table_A "Table B" as Table_B
| eval diff=Table_B-Table_A

 

And then you can save this search as an alert and have the alert triggered if diff>3.

---
If you find the answer helpful, an upvote/karma is appreciated
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti &#x1f389; —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...