Splunk Search

How to compare 2 filename%y%m%d.csv from month appart?

New Member

Hi fellows!

I have a scheduled job that output a single host list (in a unique Table) every day. the filename is automaticly named to filename_currentdate.csv

What i'm trying to achieve is compare two .csv from a month apart and show the result in the dashboard. I need this to run as a scheduled job too...

You guys have any idea? I'm kinda stuck!

0 Karma


hello there,

couple related answers here:

in general, try something like this:
| inputlookup <LOOKUP1> | lookup <LOOKUP2> ...
hope it helps

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!