Hi,
I have two events:
event1: field1="A",field2="ABC",.....,fieldN="12"
event2: field1="B",field2="ABC",.....,fieldN="13"
Is it possible to do a query to find the difference between these events?
I don't know the amount of the fields, I want to compare all event fields and check if there is something different.
How can I do this?
Thanks.
HI,
have a look at the diff command
https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchReference/Diff
Example 2:
Compare the 9th search results to the 10th.
... | diff position1=9 position2=10
If I have the following query:
index=A source=fileA.csv | append [search index=A source=fileB.csv] | diff ...?
How can I use the diff on this case?