Splunk Search

How to compare two matching field from two look up table?

abi2023
Path Finder

I have two lookup table call lookup1.csv and lookup2.csv both has matching field call fullname.
I want match my lookup1.csv to lookup2.csv and output the value not in the lookup1.csv byt in the lookup2.csv?

| inputlookup lookup1.csv | search NOT [| inputlookup lookup.csv | field fullname]

but this SPL displaying result found in the both look table. Is any way to do this in splunk?

 

ADDVANCE Thanks

Labels (2)
Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your query is pretty close.  Try the where option to inputlookup and use the format command to put the subsearch results in the right format.

| inputlookup lookup1.csv where NOT [| inputlookup lookup.csv | field fullname | format ]

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...