Splunk Search

compare two fields with against other field not in order

kirrusk
Communicator

Hi 

 

I'm trying to compare two fields against one field, can anyone please suggest how can I achieve this.

Cluster           pronames1   pronames2    pronames3
CLUSTER1       PRO2                PRO1                 PRO1
CLUSTER1       PRO2                PRO2                 PRO2
CLUSTER1       PRO3                PRO4                 PRO4
CLUSTER1       PRO3                PRO4                 PRO3
CLUSTER1       PRO1                PRO5                 PRO5
CLUSTER1       PRO8                PRO2                 PRO8

here my intention is to compare   (pronames1 == pronames2) and (pronames1== pronames3)
but all three fields are not in order.

The expected result should be, display pronames2 and pronames3 not in pronames1

like below

Cluster                      pronames2    pronames3
CLUSTER1                     PRO4                PRO4
CLUSTER1                     PRO5                PRO5
CLUSTER1                      n/a                    PRO8

 

@gcusello 

Labels (4)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

To drop a field simply

| fields - pronames1

It is not clear how you are comparing the fields so that you get the expected results. Can you explain what you are trying to do in more detail?

0 Karma

kirrusk
Communicator

@ITWhisperer  I'm trying to compare pronames2 fields values against pronames1 & pronames3 against pronames1

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval result=if(pronames1==pronames2,if(pronames1=pronames3,"match","no match"),"no match")
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...