Dear Experts ,
I have created the Lookup Hostname.csv(Contain only one field Hostname) which contain 100 number of hosts. I need to write a search to compare the hostname.csv with current search(List of unique hostname ) to get the new hostname come to network comparing with hostname.csv.
Lets say 101 , a new host came to network . Need to compare with hostname.csv . Display in search output
sourcetype=foo NOT [inputlookup hostname.csv | fields+ host]
| stats values(host) AS new_hosts
The subsearch will exclude all known hosts from the list, so only new hosts are shown in the results
sourcetype=foo NOT [inputlookup hostname.csv | fields+ host]
| stats values(host) AS new_hosts
The subsearch will exclude all known hosts from the list, so only new hosts are shown in the results
hmm, did not work for me until I did:
index=blah [inputlookup hostname.csv | table host] | stats values(host) AS "Hosts appearing in Splunk, not on my list"
didn't use the "fields+"