I have a scripted input that takes in rpm -qa output and want to find out the difference in packages installed on two hosts. What kind of search can get this done?
For an rpm -qa output, you will need to create multiple values via multikv and leverage a sub search that returns the packages that exist on one of the hosts:
host=host1 sourcetype=rpm | multikv noheader=t | rex "(?
It is important to note that this solves the problem of using "diff", as that will not give you discrete package information.
For an rpm -qa output, you will need to create multiple values via multikv and leverage a sub search that returns the packages that exist on one of the hosts:
host=host1 sourcetype=rpm | multikv noheader=t | rex "(?
It is important to note that this solves the problem of using "diff", as that will not give you discrete package information.