Splunk Search

How to calcualte the count diff between 2 searches?

jerrytao
New Member

index=A | stats count as count1
index=A | dedup field1 field2 | stats count as count2

This 2 searched have same index A, then I want to calculate (count1-count2).

Anyone can help on this? Thanks in advance!

Tags (2)
0 Karma
1 Solution

vnravikumar
Champion

Hi

Try this

index=A | stats count as count1
| appendcols 
    [| search index=A | dedup field1 field2 | stats count as count2] |eval diff = count1-count2

View solution in original post

0 Karma

vnravikumar
Champion

Hi

Try this

index=A | stats count as count1
| appendcols 
    [| search index=A | dedup field1 field2 | stats count as count2] |eval diff = count1-count2
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...