Splunk Search

Compare several fields from 2 indexes

Luninho
Explorer

I have two indexes: INDEX1 and INDEX2. In these indexes have the same fields: FIELD1, FIELD2, FIELD3 but they can have different values. 

For example:
INDEX1: FIELD1=5, FIELD2=8
INDEX1: FIELD1=5, FIELD2=7

I need to get a table where will be show only fields with different values in different indexes. According the previous example:

|INDEX1|FIELD2=8|
|INDEX2|FIELD2=7|
or something similar

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which field or fields is/are used to join the two indexes so that a comparison between the other fields in the event can be sensibly made?

0 Karma

Luninho
Explorer

forget to add these fields in question. I use field @"TIMEIN"

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

see the answer here for hints

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...