I'm looking for a report that can import a csv file of hosts and display the event count for the past 7 days. This csv file may have systems that have never reported to splunk and thus may have a count of zero. I can get a report that list hosts with count > 0, but it won't list the ones where count = 0. Any help would be appreciated.
I finally found something that works, but it is a slow way of doing it.
index=* [|inputcsv allhosts.csv] | stats count by host | stats count AS totalReportingHosts| appendcols [| inputlookup allhosts.csv | stats count AS totalAssets]
sure. thanks for the offer of help. my search looks like this
index=* [|inputcsv allhosts.csv] | stats count by host
and my csv file looks like this
It reports counts from the "good" hosts, but won't report a 0 from the "unknown" host
Assuming you have the csv file added as lookup table, try something like this
|inputcsv allhosts.csv | eval count=0 | join type=left host [search index=* [|inputcsv allhosts.csv] | stats count by host]