Splunk Search

How to compare two matching field from two look up table?

abi2023
Path Finder

I have two lookup table call lookup1.csv and lookup2.csv both has matching field call fullname.
I want match my lookup1.csv to lookup2.csv and output the value not in the lookup1.csv byt in the lookup2.csv?

| inputlookup lookup1.csv | search NOT [| inputlookup lookup.csv | field fullname]

but this SPL displaying result found in the both look table. Is any way to do this in splunk?

 

ADDVANCE Thanks

Labels (2)
Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your query is pretty close.  Try the where option to inputlookup and use the format command to put the subsearch results in the right format.

| inputlookup lookup1.csv where NOT [| inputlookup lookup.csv | field fullname | format ]

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...