Splunk Search

search query help

shri_27
Path Finder

Hi all,
I have 2 files, where suplierID,contractID are the common fields, Now I want to exclude the values of these fieds from 1st file if the value pair is present in 2nd file.how to achieve this??
plese help me for this.

Thanks in advance

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

source=file1 NOT [search source=file2 | fields + suplierID contractID]

The subsearch gets executed first and returns the key/value pairs for the the two fields in question and then the outer search gets executed like so;

source=file1 NOT (( suplierID=X AND contractID=Y ) OR ( suplierID=X AND contractID=Z ) OR ... )

/K

Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...