Reporting

How to combine two lookups for a report?

revanthammineni
Path Finder

Hi Everyone,

I'm working on combining two lookups for a certain report.

My question is:

Let's say I have a first  look up named hosts.csv with hosts a,b,c,d,e,f

and I have a second lookup decom.csv with hosts a,b,c.

 

I want to compare two lookups  and take off the values of second lookup in the first lookup. So, I should get just the "d,e,f"..

Please help me how to solve this.

TIA.

Labels (1)
Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Here's one untested way to do it.  It assumes both lookups have the same column name "foo".

| inputlookup hosts.csv where NOT [ | inputlookup decom.csv | fields foo | format ]

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

revanthammineni
Path Finder

Thanks for the reply. May I know why we are using format command here. I know, that format puts the data into  a single value but I don't really understand why you suggesting here.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...