Monitoring Splunk

How to get the difference of value between two tables?

aaa2324
Explorer

Hi Team,

I need to find difference between two tables and generate an alert when the diffence between Table B and Table A is greater than 3 and publish the diffence in table. Kindly help on this

Table A       Table B   

3234          3240

4234           4236

2345           2348

1345           1349

Labels (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @aaa2324 ,

Try renaming the columns in the table and remove the spaces in the column name and then you'll be able to calculate the difference easily. Your query should look something like below:

 

<<your_base_query>>
| rename "Table A" as Table_A "Table B" as Table_B
| eval diff=Table_B-Table_A

 

And then you can save this search as an alert and have the alert triggered if diff>3.

---
If you find the answer helpful, an upvote/karma is appreciated
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...