Splunk Search

How to compare 2 filename%y%m%d.csv from month appart?

New Member

Hi fellows!

I have a scheduled job that output a single host list (in a unique Table) every day. the filename is automaticly named to filename_currentdate.csv

What i'm trying to achieve is compare two .csv from a month apart and show the result in the dashboard. I need this to run as a scheduled job too...

You guys have any idea? I'm kinda stuck!

0 Karma


hello there,

couple related answers here:

in general, try something like this:
| inputlookup <LOOKUP1> | lookup <LOOKUP2> ...
hope it helps

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!