Splunk Search

How to compare 2 filename%y%m%d.csv from month appart?

R1k
New Member

Hi fellows!

I have a scheduled job that output a single host list (in a unique Table) every day. the filename is automaticly named to filename_currentdate.csv

What i'm trying to achieve is compare two .csv from a month apart and show the result in the dashboard. I need this to run as a scheduled job too...

You guys have any idea? I'm kinda stuck!

0 Karma

adonio
Ultra Champion

hello there,

couple related answers here:
https://answers.splunk.com/answers/553238/how-do-i-compare-two-lookups-formed-from-reports-w.html
https://answers.splunk.com/answers/588461/comparing-two-lookup-files.html

in general, try something like this:
| inputlookup <LOOKUP1> | lookup <LOOKUP2> ...
hope it helps

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...