Splunk Search

compare linecount for files

EricPartington
Communicator

I am using splunk to compare the output of routes from a list of firewalls. The output contains a listing of routes. I would like to compare the linecount from each pair member to make sure that the routes are added to each firewall properly.

I have field called cluster that associates the pair members (host)

host1-p,host1
host1-b,host1

I have a few hundred of these files to compare. I would like to build a view that shows the listing of cluster or hosts where the linecount is not the same between cluster members.

I will use that to investigate further. I can get the files into splunk and into an index.

How can I compare (subtract linecounts and if sum is non-0 show) the latest output for each cluster?

This gets me the data to compare

index=fw_audits eventtype=routes earliest=-14d | table cluster,host,linecount

Any thoughts how to do the compare between cluster members?

0 Karma
1 Solution

EricPartington
Communicator

solved using the range() operator

View solution in original post

0 Karma

EricPartington
Communicator

solved using the range() operator

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...