Splunk Search

Subtract events of two searches

Katsche
Path Finder

Hi all,

I have two searches here, which are nearly the same (5 Events more at one of them).
Is it somehow possible to Subtract the 289 events of the first search from the 294 other events of the second search?

Kind regards,
Katsche

Tags (1)
0 Karma
1 Solution

Paolo_Prigione
Builder
0 Karma

Paolo_Prigione
Builder

Can the set command help you?

0 Karma

Katsche
Path Finder

Sadly there is not... but a new machine is already ordered. (12 CPU cores plus Hyperthreading instead of 2 cores witouht Hyperthreading and 96GB instead of 2GB RAM, that should work! xD)

0 Karma

Paolo_Prigione
Builder

ouch... I think Splunk doesn't provide a "| addRAM" command OOTB... 🙂

0 Karma

Katsche
Path Finder

Ok, this is the answer, but I will have to figure out something else, because there is not enough RAM on my machine to run such a strong search...

0 Karma

Katsche
Path Finder

Just checked the Search Reference Manual. Looks very promising. Let me run my search and I will get back to you. 🙂

0 Karma

Katsche
Path Finder

I'd like to now the 5 events which are more.

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...