<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic All hosts without specific event in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656025#M226569</link>
    <description>&lt;P&gt;Hello Splunk Community,&lt;/P&gt;&lt;P&gt;I'm trying to write a query to show me a chart (or table) for all hosts in my index in the last 45 min that haven't written a specific string to a log. The below query shows me that it has happened on a single host, but I want two columns in a table: column 1 showing the host name and&amp;nbsp;column 2 showing how many times that string appeared in that log (including all the hosts with 0 times).&lt;/P&gt;&lt;P&gt;Query so far:&lt;/P&gt;&lt;P&gt;index="index" source="C:\\Windows\\System32\\LogFiles\\Log.log" "Detection!" earliest=-45m latest=now | stats count by host&lt;/P&gt;</description>
    <pubDate>Tue, 29 Aug 2023 23:09:52 GMT</pubDate>
    <dc:creator>erick4x4</dc:creator>
    <dc:date>2023-08-29T23:09:52Z</dc:date>
    <item>
      <title>All hosts without specific event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656025#M226569</link>
      <description>&lt;P&gt;Hello Splunk Community,&lt;/P&gt;&lt;P&gt;I'm trying to write a query to show me a chart (or table) for all hosts in my index in the last 45 min that haven't written a specific string to a log. The below query shows me that it has happened on a single host, but I want two columns in a table: column 1 showing the host name and&amp;nbsp;column 2 showing how many times that string appeared in that log (including all the hosts with 0 times).&lt;/P&gt;&lt;P&gt;Query so far:&lt;/P&gt;&lt;P&gt;index="index" source="C:\\Windows\\System32\\LogFiles\\Log.log" "Detection!" earliest=-45m latest=now | stats count by host&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 23:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656025#M226569</guid>
      <dc:creator>erick4x4</dc:creator>
      <dc:date>2023-08-29T23:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: All hosts without specific event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656029#M226571</link>
      <description>&lt;P&gt;If data is not in an index, Splunk cannot create what is not there, so to solve this type of problem you have to&lt;/P&gt;&lt;P&gt;a) get the data of events for hosts that DO write to the index&lt;/P&gt;&lt;P&gt;b) append a list of hosts you want to know about from a lookup file&lt;/P&gt;&lt;P&gt;i.e. your search will look something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="index" source="C:\\Windows\\System32\\LogFiles\\Log.log" "Detection!" earliest=-45m latest=now 
| stats count by host
``` This bit gets all the hosts you want to know about and just contains a field called host ```
| append [ 
  | inputlookup list_of_wanted_hosts.csv
  | eval count=0
]
``` now this joins all together, so you have a list with the counts found and 0 where no data is present ```
| stats max(count) as count by host&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 29 Aug 2023 23:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656029#M226571</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-08-29T23:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: All hosts without specific event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656156#M226628</link>
      <description>&lt;P&gt;Thank you for the reply. I wasn't clear enough about the hosts already being in the index. If I run this query:&lt;/P&gt;&lt;P&gt;index="index" source="C:\\Windows\\System32\\LogFiles\\Log.log" earliest=-45m latest=now&lt;/P&gt;&lt;P&gt;I have 34 hosts listed. That Log.log is used for many things. It is constantly being updated. I want to know which hosts have had that Log.log updated but don't have the string "Detection!"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 19:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656156#M226628</guid>
      <dc:creator>erick4x4</dc:creator>
      <dc:date>2023-08-30T19:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: All hosts without specific event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656162#M226633</link>
      <description>&lt;P&gt;Essentially, I'm trying to create a checklist of hosts I manage and which ones haven't had this event occur yet. This is the first half of what I want:&lt;/P&gt;&lt;P&gt;index="index" source="C:\\Windows\\System32\\LogFiles\\Log.log" "Detection!" earliest=-45m latest=now | chart count by host&lt;/P&gt;&lt;P&gt;This query shows me 2 columns: host and # of times "Detection!" happened. I just need a 3rd column&amp;nbsp; or a continuation of the 2nd column that shows hosts with count 0 so I know which ones I still need to work on.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 22:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656162#M226633</guid>
      <dc:creator>erick4x4</dc:creator>
      <dc:date>2023-08-30T22:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: All hosts without specific event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656171#M226637</link>
      <description>&lt;P&gt;OK, so if ALL your hosts are in the logs, you just need this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="index" source="C:\\Windows\\System32\\LogFiles\\Log.log" earliest=-45m latest=now 
| eval Detection=if(match(_raw, "Detection!"), 1, 0)
| stats sum(Detection) as Detections by host&lt;/LI-CODE&gt;&lt;P&gt;This finds all events from Log.Log and then line 2 sets the value of a new field to 1 if the word "Detection!" is found in the event.&lt;/P&gt;&lt;P&gt;Then the stats will add together all the Detection events for each host&lt;/P&gt;&lt;P&gt;This is a key technique in Splunk for getting different sets of information from the same data, by first selecting ALL the data you want to consider and then using the &lt;STRONG&gt;eval&lt;/STRONG&gt; statement (Splunk's Swiss Army knife) to set some indicator (in this case, determining if a particular event is the one you are really interested in counting) and then the stats just adds up all detections.&lt;/P&gt;&lt;P&gt;This hosts that do NOT have the Detection! word, will always have Detection=0, so will end up with a&amp;nbsp;Detections column value of 0&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 23:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656171#M226637</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-08-30T23:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: All hosts without specific event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656333#M226694</link>
      <description>&lt;P&gt;This is exactly what I needed. Thank you so much!&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 21:08:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/All-hosts-without-specific-event/m-p/656333#M226694</guid>
      <dc:creator>erick4x4</dc:creator>
      <dc:date>2023-08-31T21:08:38Z</dc:date>
    </item>
  </channel>
</rss>

