Splunk Search

How to compare search results using csv as input containing two columns - and show difference (present and absent)

itsppp1234
New Member

I need to search using the input from csv and compare the results with the same csv containing two columns - and show the difference between them (accountname present and accountname absent)

eventcode=4768 contains Account_Name in NTID format

eventcode=4769 contains Account_Name in UPN format

index=<index_name> host=<host_list> EventCode=4768 OR EventCode=4769 [| inputlookup accountname.csv] | dedup Account_Name | table Account_Name, Ticket_Encryption_Type, Supplied_Realm_Name, Service_Name,Service_ID

how do I make the results from above query to show the difference?

Appreciate the help.

Thanks

0 Karma

itsppp1234
New Member

Also, how do I get it to search for both EventCode above.

Currently, it is only searching for a 4768 or 4769 due to the change in the value format of Account_Name field.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...