Splunk Search

Compare several fields from 2 indexes

Luninho
Explorer

I have two indexes: INDEX1 and INDEX2. In these indexes have the same fields: FIELD1, FIELD2, FIELD3 but they can have different values. 

For example:
INDEX1: FIELD1=5, FIELD2=8
INDEX1: FIELD1=5, FIELD2=7

I need to get a table where will be show only fields with different values in different indexes. According the previous example:

|INDEX1|FIELD2=8|
|INDEX2|FIELD2=7|
or something similar

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which field or fields is/are used to join the two indexes so that a comparison between the other fields in the event can be sensibly made?

0 Karma

Luninho
Explorer

forget to add these fields in question. I use field @"TIMEIN"

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

see the answer here for hints

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...