Splunk Search

compare row by row values

kirrusk
Communicator

Hi All,

 

i'm trying to compare row values .

my table is like 

 

App           label                   env         space

mini1       jenkins-a21        p1          1290           

mini2       jenkins-a22       p1            1687

mini2      jenkins-a21         p2          1290

mini3       jenkins-a23         p2           1598

mini4      jenkins-a24          p1           1687

mini3       jenkins-b23          p1           1598

 

output should be like 

App           label                      env           space          Result

mini1       jenkins-a21          p1            1290       matched       (comparing label values for p1 and p2)

mini2       jenkins-a21          p2           1290        matched       (comparing label value for p1 and p2)

mini3       jenkins-a23         p2           1598         not matched (comparing  label value for p1 and p2

mini3       jenkins-b23          p1           1598        not matched   (comparing label label for p1 and p2)

 

@woodcock 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear what the goal is.  Please provide a sample of the desired output.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kirrusk
Communicator

@richgalloway  updated question

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...