<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerting in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670524#M229848</link>
    <description>&lt;P&gt;In splunk terminolgy it's not called "query" but "search".&lt;/P&gt;&lt;P&gt;Anyway, it's a common question how to "find" something that's not there.&lt;/P&gt;&lt;P&gt;See &lt;A href="https://www.duanewaddle.com/proving-a-negative/" target="_blank"&gt;https://www.duanewaddle.com/proving-a-negative/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Dec 2023 11:44:34 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-12-02T11:44:34Z</dc:date>
    <item>
      <title>How to find non-monitored hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670523#M229847</link>
      <description>&lt;P&gt;Hey All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’m a splunk beginner I'm looking to create a query that to be used&lt;/SPAN&gt;&amp;nbsp; &lt;SPAN&gt;as an alert, specifically to identify servers not in the&amp;nbsp;&lt;/SPAN&gt;_&lt;SPAN&gt;inventory – those not being monitored by Splunk. If anyone could share insights, examples&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank You&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 11:47:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670523#M229847</guid>
      <dc:creator>Muthu_Vinith</dc:creator>
      <dc:date>2023-12-02T11:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670524#M229848</link>
      <description>&lt;P&gt;In splunk terminolgy it's not called "query" but "search".&lt;/P&gt;&lt;P&gt;Anyway, it's a common question how to "find" something that's not there.&lt;/P&gt;&lt;P&gt;See &lt;A href="https://www.duanewaddle.com/proving-a-negative/" target="_blank"&gt;https://www.duanewaddle.com/proving-a-negative/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 11:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670524#M229848</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-02T11:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670525#M229849</link>
      <description>&lt;P&gt;Splunk is not good at finding things that aren't there - essentially, you would have to provide a list of all the servers you expect to find and discount all those that you do find, leaving you a list of servers which haven't been found.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 11:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670525#M229849</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-12-02T11:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670607#M229874</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I’ve a scenario where I want to compare of events from &lt;/SPAN&gt;index=abc host=_inventory&lt;SPAN&gt; and &amp;nbsp;data from a lookup file that includes fields such as &lt;/SPAN&gt;host&lt;SPAN&gt;, &lt;/SPAN&gt;location&lt;SPAN&gt;, &lt;/SPAN&gt;os&lt;SPAN&gt;, etc. The end goal is to point out servers that aren't being reported by Splunk. The structure of my Splunk events includes fields like &lt;/SPAN&gt;location&lt;SPAN&gt;, &lt;/SPAN&gt;tier&lt;SPAN&gt;, &lt;/SPAN&gt;servers&lt;SPAN&gt;, and &lt;/SPAN&gt;splunk_server&lt;SPAN&gt;. In the lookup file, I have fields like &lt;/SPAN&gt;host&lt;SPAN&gt;, &lt;/SPAN&gt;location&lt;SPAN&gt;, &lt;/SPAN&gt;os&lt;SPAN&gt;, and more&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I combined two data’s and what is the search condition to find out how servers are being monitored&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 09:34:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670607#M229874</guid>
      <dc:creator>Muthu_Vinith</dc:creator>
      <dc:date>2023-12-04T09:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670612#M229875</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=abc
| stats count by host
| inputlookup append=t yourlookup
| fillnull count
| stats sum(count) as count by host
| where count=0&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 04 Dec 2023 10:13:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670612#M229875</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-12-04T10:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670626#M229883</link>
      <description>&lt;P&gt;This search will give results of servers that is not being reported Correct?&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 11:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670626#M229883</guid>
      <dc:creator>Muthu_Vinith</dc:creator>
      <dc:date>2023-12-04T11:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670630#M229884</link>
      <description>&lt;P&gt;That's the idea - try it and see&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 12:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670630#M229884</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-12-04T12:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670634#M229885</link>
      <description>&lt;P&gt;Okay Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 12:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670634#M229885</guid>
      <dc:creator>Muthu_Vinith</dc:creator>
      <dc:date>2023-12-04T12:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670749#M229909</link>
      <description>&lt;P&gt;I tired this method but it's giving me servers that is&amp;nbsp; monitored&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 04:01:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670749#M229909</guid>
      <dc:creator>Muthu_Vinith</dc:creator>
      <dc:date>2023-12-05T04:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670797#M229918</link>
      <description>&lt;P&gt;This sounds like a data issue - you should check which hosts are coming up as not being monitored and see why they are not showing up in your index.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 11:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670797#M229918</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-12-05T11:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670892#M229948</link>
      <description>&lt;P&gt;Sure&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 17:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-non-monitored-hosts/m-p/670892#M229948</guid>
      <dc:creator>Muthu_Vinith</dc:creator>
      <dc:date>2023-12-05T17:47:26Z</dc:date>
    </item>
  </channel>
</rss>

