Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Filtered search from 2 searches

$
0
0
I have 2 searches: 1. Search(AAA)|rename _time as TimeA|table TimeA host; 2. Search(BBB)|rename _time as TimeB|table TimeB host How to create a new search: Search(???)|table host; (or Search(???)|table TimeA TimeB host) Which will only list the hosts that TimeB is older(or smaller) than TimeA (there might be more than 1 results TimeA and TimeB for each host, in that case, just pick the latest one to compare)

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>