Splunk Search

Create a query to compare Asset Inventory to see if an Asset exists between data pushes?

dscott10
New Member

I am trying to create a dashboard that will showcase, between data pulls, the assets that no longer exists in the index. For example, if we have data pulls from an asset inventory database at 10am and 10pm, I would like to display the diff assets between those 2 times or each day.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...