Splunk Enterprise

Compare two searches and get the difference in table results?

piyushpandey
Engager

Hello, I have logs containing two fields "account" and "shard". 

By doing "| table account shard"
I created a table of two cols 

and since the table can have repeating values like:
account                  shard
100                           21
100                           21
100                           8
101                           10

I did "| stats dc(shard) by account", which gives me:
account                 shard
100                          2
101                          1

I have two such tables(before and after) of "account" vs "dc(shard)" and I want to compare them(get the diff in distinct no of shards for each account before and after), but struggling to do this. 
Please guide me to get the result. 
[I can explain anything thats unclear]

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Combine your searches and evaluate another field (period) with the appropriate value ("before" or "after"), then use the additional field in the stats command

| stats dc(shard) by account period
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...