Splunk Enterprise

File Compare and Display

akankshayadav
Path Finder

Consider, i have two files. File1 and File2 

File1 and File2 got indexed last month with events in file1 say A ,B  and events in file2 say C,D .

They again got indexed today, file1 with same events A and B but file2 with C,D,E,F. This means that file2 modified version has different events as compared to it's last version.

Now , i need to display in the panel all files like file2 whose current events are different from last events. 

Thanks in advance!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

ITWhisperer_0-1624266653835.png

 

0 Karma

akankshayadav
Path Finder

Yes i did try . but it isn't getting the answer.
Can you give me an approach that I can get the names of files whose events are different in different versions.
File 1 - before had events- A B   today has A C

File 2- before had - X Z today also X Z

My output desired is File1 displayed 

                    

0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...