Splunk Dev

List comparsion of field values

skillfulobj
Explorer

sample event 1:
id:12345
fcount:20
component:value1
time:2021:04:26

sample event2:
id:12346
fcount:200
component:value2
time:2021:04:26

sample event 3:
id:12347
fcount:20
component:value1
time:2021:04:27

sample event 4:
id:12348
fcount:200
component:value3
time:2021:04:27


i have list of values for my field "component" , lets say i have value1 , value2 , value3... value15 , which are coming part of my events

for given a day my events are related only to components of value1, value2 , i want to display the components which are not received for the particular given day

Example : in above 4 events on 2021:04:26 i got components of value1 and value2 where i didnt receive components for value3..to value 15 , i want to display them which not received

Tags (2)
0 Karma

skillfulobj
Explorer

@MuS  could you please share your thoughts on this

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...