Splunk Search

How to find all unmatched records in two sources type by using multiple fields?

oraclebox
Explorer

sourcetypes=ship
fields: PortId,ServiceLoopID,VesselName,ID
sourcetypes=route
fields: PORT,LOOP,VS_NAME,SID

I have two sourcetypes above, I want to find out all events in sourcetypes=ship which cannot find in sourcetypes=route.
The matching fields is PortId=PORT, ServiceLoopID=LOOP, VesselName=VS_NAME, ID=SID, how can I do it?

Tags (3)
0 Karma

somesoni2
Revered Legend

Try this

sourcetype=ship NOT [search sourcetype=route | table PORT,LOOP,VS_NAME,SID| rename PORT as PortId, Loop as ServiceLoopID, VS_NAME as VesselName, SID as ID ] | table PortId,ServiceLoopID,VesselName,ID
0 Karma
Get Updates on the Splunk Community!

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...