Splunk Search

Set difference between two output of two query

Nilesh067
Explorer

I have two query i want to get those result that are in query 1 but not in query 2

Query 1 :

index=APP_SERVER- source=API_LOG "Error while create record for customer id*" |rex "customer id : (?<custId>.*\w+)" |dedup custId |table custId

Output :

94ABGH0048

902SDKK557

902SGHT224

902SLWT720

 

Query 2 :

index=APP_SERVER- source=API_LOGS  "Successfully created record for customer id*" |rex "customer id : (?<custId>.*\w+)" |dedup custId |table custId

Output :

945TTFK0548

94ABGH0048

902SLWT720

 

I want below output out of both query ,it means these id are in query 1 result but not in query 2 result

 

902SDKK557

902SGHT224

Labels (6)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This should do it.

 

index=APP_SERVER- source=API_LOG "Error while create record for customer id*" 
| rex "customer id : (?<custId>.*\w+)" 
| search NOT [search index=APP_SERVER- source=API_LOGS  "Successfully created record for customer id*" |rex "customer id : (?<custId>.*\w+)" | return custId]
| dedup custId 
| table custId 

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Nilesh067
Explorer

@richgalloway 
it is showing, Unknown search command 'index'.

0 Karma

richgalloway
SplunkTrust
SplunkTrust
I've corrected my reply.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...