Hello,
I'm trying to create a search that shows what results are missing today - a, compared to yesterday - b.
a and b are inputs on a dashbaord so I could also compare 2 weeks ago with today.
I can't do a "search of today NOT [subsearch with results from yesterday] because I need to use | operations before.
It feels like a simple problem that for sure was solved 100 times but I don't get it.
What I have so far is only the difference, but it also shows if something new was added today, but was not there yesterday.
index=myindex sourcetype=special_list
| eval deleted=case(Deleted="Yes", "Deleted", Deleted="No", "Active")
| eval date=strftime(_time, "%F")
| where date="2019-09-27" OR date="2019-09-26"
| stats count as Total by FullName
| where Total=1
Example:
Compare 2019-09-22
with 2019-09-27
Result: C
Any help highly appreciated
Cheers
Hi ABurk,
try something like this
index=myindex sourcetype=special_list
| eval deleted=case(Deleted="Yes", "Deleted", Deleted="No", "Active")
| eval date=strftime(_time, "%F")
| where date="2019-09-27" OR date="2019-09-26"
| stats values(date) AS date count as Total by FullName
| where Total=1 AND date="2019-09-27"
if it doesn't run use "search" instead "where".
Bye.
Giuseppe
Hi ABurk,
try something like this
index=myindex sourcetype=special_list
| eval deleted=case(Deleted="Yes", "Deleted", Deleted="No", "Active")
| eval date=strftime(_time, "%F")
| where date="2019-09-27" OR date="2019-09-26"
| stats values(date) AS date count as Total by FullName
| where Total=1 AND date="2019-09-27"
if it doesn't run use "search" instead "where".
Bye.
Giuseppe
Thanks for the answer, I used
index=myindex sourcetype=special_list
| eval date=strftime(_time, "%F")
| where date like "2019-09-27"
| search NOT
[search index=myindex sourcetype=special_list
| eval date=strftime(_time, "%F")
| where date like "2019-09-26"
| eventstats count by FullName
| table FullName]
| eventstats count by FullName
| table FullName, Path
I think I did some syntax wrong with the |search in the past because I'm sure I tried before..
Hi ABurk,
Your search should correctly run if you're sure that your subsearch has less than 50,000 results.
Bye, see next time.
Giuseppe