Hi Splunk Experts,
I need to create a report to display the table record count difference between two databases during a period of time.
Events (list) are captured as follow:
db_name table_name row_count
x a 4
x b 3
y a 4
y b 1
Report should look like this:
table_name x y rec_diff
a 4 4 0
b 3 1 2
Any help will be very appreciated.
↧