Splunk Search

Comparing differences in the same field depending on the row grouping field

jo54
Explorer

I'll try to explain it with a basic example. As an output of a stats command I have:

detectionquery
search1
google.com
yahoo.com
search2
google.com
bing.com

 

I want to get which queries are not being detected by both search1 and search 2. Or else, getting rid of the queries that are in both searches, either way work. Like ok, search1 is detecting yahoo.com whereas search2 isn't, and viceversa with bing.com

I thought about grouping by query instead of by search,  the problem is I have dozens or even hundreds of queries.

Any thoughts? Cheers

Labels (2)
0 Karma
1 Solution

marnall
Motivator

You could stats count by query. Queries that are found by both detections will have count=2, while queries that are found by only one will have count=1. Then you can filter for count=1 to remove the hundreds of queries that are found by both detections.

| stats count by query
| where count = 1

 

View solution in original post

0 Karma

marnall
Motivator

You could stats count by query. Queries that are found by both detections will have count=2, while queries that are found by only one will have count=1. Then you can filter for count=1 to remove the hundreds of queries that are found by both detections.

| stats count by query
| where count = 1

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats count by query
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...