Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Find the details about the result of set diff.

$
0
0
I am using two searches Search1 search 2 1 1 2 2 3 3 5 4 Using set diff gives me the result. Dont want to use join. set diff [search index=ABC sourcetype=PQRS| stats count by x_orderno | fields - count] [search index=DEF sourcetype=WXYZ| stats count by x_orderno | fields - count] x_orderno 5 4 I want the result as x_orderno sourcetype 5 PQRS 4 WXYZ Kindly suggest. TIA

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>