Alerting

Splunk Alert if host on lookup stops sending data

scout29
Path Finder

Looking to create an alert if a host on a lookup stops sending data to Splunk index=abc. I have created a lookup called hosts.csv with all the hosts expected to be logging for a data source. Now i need to create a search/alert that notifies me if a host on this lookup stops sending data to index=abc

I was trying something like this  search below, but now having much luck:

| tstats count where index=abc host NOT [| inputlookup hosts.csv] by host

 

The lookup called hosts.csv is formatted with the column name being host, for example like:

 

host

hostname101

hostname102

hostname103

hostname104

 

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @scout29 ,

please try something like this:

| tstats count where index=abc BY host 
| append [ | inputlookup hosts.csv | eval count=0 | fields host count]
| stats sum(count) AS total BY host
| where total=0

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @scout29 ,

please try something like this:

| tstats count where index=abc BY host 
| append [ | inputlookup hosts.csv | eval count=0 | fields host count]
| stats sum(count) AS total BY host
| where total=0

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @scout29 

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...