Splunk Search

How to compare Field Values of Two Different Fields from Two Lookups?

atebysandwich
Path Finder
|inputlookup lookup1,csv
|fields IP Host_Auth
|lookup lookup2.csv IP output Host_Auth as Host_Auth.1

Some of the field values in each version of Host_Auth match and some don't. How can I find the events that do not match?

I've tried where Host_Auth != Host_Auth.1 and eval but nothing works

Labels (2)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

Let me take a guess: you can do yourself a favor by not naming fields with special characters.

|inputlookup lookup1,csv
|fields IP Host_Auth
|lookup lookup2.csv IP output Host_Auth as Host_Auth_1
| where Host_Auth != Host_Auth_1

When field name contains special characters, you need to use single quotes in order to dereference their values, like

|inputlookup lookup1,csv
|fields IP Host_Auth
|lookup lookup2.csv IP output Host_Auth as Host_Auth.1
| where Host_Auth != 'Host_Auth.1'

View solution in original post

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Let me take a guess: you can do yourself a favor by not naming fields with special characters.

|inputlookup lookup1,csv
|fields IP Host_Auth
|lookup lookup2.csv IP output Host_Auth as Host_Auth_1
| where Host_Auth != Host_Auth_1

When field name contains special characters, you need to use single quotes in order to dereference their values, like

|inputlookup lookup1,csv
|fields IP Host_Auth
|lookup lookup2.csv IP output Host_Auth as Host_Auth.1
| where Host_Auth != 'Host_Auth.1'
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...