Splunk Search

Comparing / diffing 2 lookup tables

oleg106
Explorer

Hello,

I have 2 CSV lookups updating several times a day.  One (A) is from CMDB with the entire list of assets (hostname, ip, user, os, etc).  The other (B) is a list of installed clients for some product, also containing the hostname.  I would like to get a search/dashboard that lists hosts in A that are not found in B with some of  additional fields.  Have no found a way to do with with 2 lookups, any ideas?  Thanks!

Lookup CSV A: Host1, Host2, Host3
Lookup CSV B: Host1, Host3
Search output: Host2

 

Labels (1)
0 Karma

crlunde
Loves-to-Learn Everything

I am also looking for this same information. Anyone have an answer for this?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...