Splunk Search

compare two fields with against other field not in order

kirrusk
Communicator

Hi 

 

I'm trying to compare two fields against one field, can anyone please suggest how can I achieve this.

Cluster           pronames1   pronames2    pronames3
CLUSTER1       PRO2                PRO1                 PRO1
CLUSTER1       PRO2                PRO2                 PRO2
CLUSTER1       PRO3                PRO4                 PRO4
CLUSTER1       PRO3                PRO4                 PRO3
CLUSTER1       PRO1                PRO5                 PRO5
CLUSTER1       PRO8                PRO2                 PRO8

here my intention is to compare   (pronames1 == pronames2) and (pronames1== pronames3)
but all three fields are not in order.

The expected result should be, display pronames2 and pronames3 not in pronames1

like below

Cluster                      pronames2    pronames3
CLUSTER1                     PRO4                PRO4
CLUSTER1                     PRO5                PRO5
CLUSTER1                      n/a                    PRO8

 

@gcusello 

Labels (4)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

To drop a field simply

| fields - pronames1

It is not clear how you are comparing the fields so that you get the expected results. Can you explain what you are trying to do in more detail?

0 Karma

kirrusk
Communicator

@ITWhisperer  I'm trying to compare pronames2 fields values against pronames1 & pronames3 against pronames1

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval result=if(pronames1==pronames2,if(pronames1=pronames3,"match","no match"),"no match")
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...