Hi All,
I am new to Splunk and need some help.
I have 2 index, and in both index there is a field "ip", How can I find the records which are not exists in second index?
For eg:
1.1.1.2, test.com
1.2.3.4 test1.com
2.3.4.5 test2.com
3.4.5.6 test3.com
1.2.3.4 test1.com
3.4.5.6 test3.com
1.1.1.2, test.com
2.3.4.5 test2.com
Please help...
Thanks
Try this
index=indexA NOT [search index=indexB | stats count by ip | table ip]