Reporting

Litigation Hold status

ajromero
Path Finder

I have a litigation hold report and I need to display if the account is disable. I created a lookup table so I can display user full and if the account is disable. when I pull data from the lookup table I can't display the status

Here is my search

eventtype=msexchange-mailbox-usage Database="*" Database="*" LitigationHoldEnabled=True |dedup User
|table User, TotalDeletedItemSize, TotalItemSize, Database, Total, LitigationHoldEnable
|addtotals fieldname=Total
| lookup ActiveDirectoryUsers.csv User OUTPUT name
|stats max(Total) as Total by name, Database

|eval Total=round((Total/1000/1000/1000),2)
|rename name as "Mailbox User Name",Total as "Mailbox Size (GB)"

in the lookup table I have  this: name, User, status

for example : name: Rumer, Shelly, status: disable

in my final report all I see the name, database, total 

i'm not able to display the status

 

thank you

Tags (1)
0 Karma
1 Solution

to4kawa
Ultra Champion

eventtype=msexchange-mailbox-usage Database="*" Database="*" LitigationHoldEnabled=True
| dedup User
| table User, TotalDeletedItemSize, TotalItemSize, Database, Total, LitigationHoldEnable
| addtotals fieldname=Total
| stats max(Total) as Total by User, Database
| lookup ActiveDirectoryUsers.csv User OUTPUT name, status
| eval Total=round((Total/1000/1000/1000),2)
| rename name as "Mailbox User Name",Total as "Mailbox Size (GB)"
| fields - User

View solution in original post

to4kawa
Ultra Champion

eventtype=msexchange-mailbox-usage Database="*" Database="*" LitigationHoldEnabled=True
| dedup User
| table User, TotalDeletedItemSize, TotalItemSize, Database, Total, LitigationHoldEnable
| addtotals fieldname=Total
| stats max(Total) as Total by User, Database
| lookup ActiveDirectoryUsers.csv User OUTPUT name, status
| eval Total=round((Total/1000/1000/1000),2)
| rename name as "Mailbox User Name",Total as "Mailbox Size (GB)"
| fields - User

Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...