Splunk Search

How to find delta between two tables?

damucka
Builder

Hello,

I am trying to find the delta between two tables, but somehow failing with it. My code is as follows:

  | table host_to_report    

  |append 
  [
  |inputlookup anomalies 
  | dedup host 
  | eval hosts_with_anomalies = host 
  | table hosts_with_anomalies
  ]

Now, I would like to get the entries of the host_to_report which are NOT present in the hosts_with_anomalies.
How would I do this easiest?

Kind Regards,
Kamil

Tags (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hello @damucka,

Try below search:

| set diff [<your first query> | table host_to_report]  [|inputlookup anomalies | dedup host | rename host as host_to_report]

Hope this helps!!!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...