I'm trying to create a dashboard for my pair critical devices. I'm not sure what is wrong with my code or if it is the token. When I click on submit, I'm getting the error: Search is waiting for input.
See below my query:
(| inputlookup critical_devices.csv
| eval SplunkHost=lower(SplunkHost)
| join SplunkHost type=outer
[| metadata index=my indexes type=hosts
| rename totalCount as Count, host as SplunkHost, lastTime as "Last Event"
| eval actualhourslag=(now()-'Last Event')/60/60
| eval SplunkHost=lower(SplunkHost)]
| fieldformat "Last Event"=strftime('Last Event', "%c")
| where actualhourslag>HoursLag OR NOT actualhourslag="*"
| stats sum(Count) by SplunkHost
| rename sum(Count) as total
| lookup critical_devices.csv SplunkHost OUTPUT PairGroup
| search PairGroup!=""
| stats count() by PairGroup
| rename count(total) as DevicesPerPairNotResponding)