Splunk Search

Compare two lookup tables

brent_weaver
Builder

Hello all... I have to compare two lookup table files in splunk. One is a list of hosts that should Be logging, and the other is a list of what isnt logging. I tried a few different things, to no avail. My goal is to build a list of what isnt logging compared to the list of what is logging.

I mean this is splunk, it cant be that hard 🙂

Tags (1)
0 Karma

sandeepmakkena
Contributor
| inputlookup lookupfile1 | lookup lookupfile2 host OUTPUTNEW host as isFound | where isnull(isFound)

Hope this helps, Thanks!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...