I am trying to use a list from a CSV file to query results for that list, but I only get a result from the first row.
The data looks like such;
workstation_1
workstation_2
workstation_3
The query looks like such;
index="wineventlog" Source_Workstation=* [inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as search] | table Source_Workstation, _time, Logon_Account | dedup Source_Workstation
Few mistakes in your search
|
character before inputlookup
index="wineventlog" Source_Workstation=* [|inputlookup test.csv | fields "Workstation Name" ...
example
index="wineventlog" [|inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as Source_Workstation] | stats count by Source_Workstation, _time, Logon_Account
Few mistakes in your search
|
character before inputlookup
index="wineventlog" Source_Workstation=* [|inputlookup test.csv | fields "Workstation Name" ...
example
index="wineventlog" [|inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as Source_Workstation] | stats count by Source_Workstation, _time, Logon_Account
Thanks for the help, but I actually figured it out. I had the following query;
index="wineventlog" Source_Workstation=* [|inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as Source_Workstation] | table Source_Workstation, _time, Logon_Account | dedup Source_Workstation
Be sure to click Accept
on this answer or post your own and accept that one. Do one or the other to close this question.
great. So the above search which I provided above, should also return similar results and would be faster as it directly uses stats count
Please upvote/accept, if it helped you