Splunk Search

search query help

shri_27
Path Finder

Hi all,
I have 2 files, where suplierID,contractID are the common fields, Now I want to exclude the values of these fieds from 1st file if the value pair is present in 2nd file.how to achieve this??
plese help me for this.

Thanks in advance

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

source=file1 NOT [search source=file2 | fields + suplierID contractID]

The subsearch gets executed first and returns the key/value pairs for the the two fields in question and then the outer search gets executed like so;

source=file1 NOT (( suplierID=X AND contractID=Y ) OR ( suplierID=X AND contractID=Z ) OR ... )

/K

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...