Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to Compare 2 fields from 2 sourcetypes and remove events that are the same and only in the second sourcetype

$
0
0
I have 2 Sourcetypes A and B with 2 important Fields SSN and Number. I want to compare all of the SSN and number's from Sourcetype A to Sourcetype B I then return Results that only show up in Sourcetype B Sourcetype A SSN number #####1111 12345 (drop this because it matches B) #####2222 12345 (drop this because it is sourcetype A even though it doesn't match) Sourcetype B SSN number #####1111 12345 (drop this because it matches A) #####2222 11111 (keep this because it doesn't match anything in A and it is Sourcetype B) I am really stuck on this one not even sure where to start.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>