<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputlookup help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558188#M158546</link>
    <description>&lt;P&gt;Rename ComputerName to host so it matches the name in the csv, then count how many times each host appear. It will be 2 if there are events in the index and the csv&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main |stats count by ComputerName
| rename ComputerName as host
| inputlookup append=t hostinventory.csv
| stats count by host&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 02 Jul 2021 17:46:05 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-07-02T17:46:05Z</dc:date>
    <item>
      <title>inputlookup help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558184#M158543</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It is the first time that I am going to use this command and the truth is I am a bit confused even though I have read about this command but the truth is not clear to me.&lt;/P&gt;&lt;P&gt;I have windows machines with the agent installed sending logs to index = main&lt;/P&gt;&lt;P&gt;I have a file in .csv with the inventory of all the machines&lt;/P&gt;&lt;P&gt;I need to get a list of the hosts that have never reported logs, either because the agent has not been installed yet or because I report logs and at a certain point I stop doing it&lt;/P&gt;&lt;P&gt;I installed the "lookup Editor" and already uploaded the inventory there.&lt;/P&gt;&lt;P&gt;Using the query | inputlookup hostinventory.csv I already get inventory information&lt;/P&gt;&lt;P&gt;But I need to make a comparison of the hosts that the index = main sees that report or have reported logs vs the inventory csv file to get an idea of ​​which hosts are reporting and which ones are not.&lt;BR /&gt;&lt;BR /&gt;in the host inventory file I have a column called "host" I need to buy it with the "host" field from the index main.&lt;BR /&gt;&lt;BR /&gt;index=main |stats count by ComputerName&amp;nbsp; (brings me the hosts that are reporting logs from the index main)&lt;BR /&gt;&lt;BR /&gt;| inputlookup hostinventory.csv (brings me the logs that are in the csv file in the field called "host")&lt;/P&gt;&lt;P&gt;but I cannot correlate the two sources of information to get a list of which hosts are reporting and which are not reporting logs&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 16:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558184#M158543</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2021-07-02T16:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558188#M158546</link>
      <description>&lt;P&gt;Rename ComputerName to host so it matches the name in the csv, then count how many times each host appear. It will be 2 if there are events in the index and the csv&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main |stats count by ComputerName
| rename ComputerName as host
| inputlookup append=t hostinventory.csv
| stats count by host&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 02 Jul 2021 17:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558188#M158546</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-02T17:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558209#M158552</link>
      <description>&lt;P&gt;Thank you very much for your valuable help.&lt;/P&gt;&lt;P&gt;I have added a &lt;STRONG&gt;where count = 2&lt;/STRONG&gt; for those who are reporting logs and &lt;STRONG&gt;where count = 1&lt;/STRONG&gt; for those who are not reporting logs&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 20:34:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-help/m-p/558209#M158552</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2021-07-02T20:34:30Z</dc:date>
    </item>
  </channel>
</rss>

