Splunk Search

Finding ip which are not exists in second index

binojmn
New Member

Hi All,

I am new to Splunk and need some help.

I have 2 index, and in both index there is a field "ip", How can I find the records which are not exists in second index?

For eg:

Index A

1.1.1.2, test.com
1.2.3.4 test1.com
2.3.4.5 test2.com
3.4.5.6 test3.com

Index B

1.2.3.4 test1.com
3.4.5.6 test3.com

Final Result (Exists in Index A, not in Index B)

1.1.1.2, test.com
2.3.4.5 test2.com

Please help...

Thanks

Tags (2)
0 Karma

somesoni2
Revered Legend

Try this

index=indexA NOT [search index=indexB | stats count by ip | table ip]
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...