Splunk Search

How to remove elements from first search with a second search?

Andresfrj
Engager

Andresfrj_0-1659450865708.png

 

Hello,

I want to perform the above operation. I have a first search (A), and want to remove elements in it (in this case a field called id) from a second search B. What is the most clean way of implementing this such search? 

 

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Andresfrj,

you have to use a subsearch.

Only limit is that a subsearch can have max 50,000 results,

so you can use something lieke this.

The rule is to identify key fields.

So if the key field is field1, you can run something like this:

index=indexA NOT [ search index=indexB | fields field1 ]
| ...

if instead subsearch can have more than 50,000 results, the solution is just a little more complex:

index=indexA OR index=indexB
| stats earliest(_time) AS _time dc(index) AS index_count values(index) AS index BY field1
| where  index_count=1 AND index=indexA

you can add to the stats command all the "values(field) AS field" you need.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Andresfrj,

you have to use a subsearch.

Only limit is that a subsearch can have max 50,000 results,

so you can use something lieke this.

The rule is to identify key fields.

So if the key field is field1, you can run something like this:

index=indexA NOT [ search index=indexB | fields field1 ]
| ...

if instead subsearch can have more than 50,000 results, the solution is just a little more complex:

index=indexA OR index=indexB
| stats earliest(_time) AS _time dc(index) AS index_count values(index) AS index BY field1
| where  index_count=1 AND index=indexA

you can add to the stats command all the "values(field) AS field" you need.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Andresfrj,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is excellent description how to avoid to use command join when you are doing “sql joins” https://community.splunk.com/t5/Splunk-Search/What-is-the-relation-between-the-Splunk-inner-left-joi...

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...