Splunk Search

How to compare a lookup field value with my current search?

AdixitSplunk
Path Finder

HI All,
I have a lookup table with host names value around 10 field name host.
I have this search index=Application sourcetype=Servers |stats count by host

I have to compare host in Lookup table with the one in above search and result should give only those host names which are not present in Lookup file.

Suppose my lookup file has below host names:

host
1
2
3
4 
5

My search gives:

host
1 
4
5

So the final result should be :

host
2
3

Thanks in advance.

Tags (2)
0 Karma
1 Solution

AdixitSplunk
Path Finder

Thanks for your reply but its not giving the right answer . The below did 🙂

index="Application" sourcetype=Servers|eval host=lower(host)|eval started_host="T"|append [inputlookup Mylookup|eval started_host="F"]|stats count(eval(started_host=="T")) as started by host|where started == 0

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

index=Application sourcetype=Servers | stats count by host | appendpipe [|inputlookup hostLookup | table host | eval sourcetype="LOOKUP"] | stats values(*) AS * dc(sourcetype) AS numDatasets BY host | search numDatasets=1 AND sourcetype="LOOKUP" | table host
0 Karma

AdixitSplunk
Path Finder

Thanks for your reply but its not giving the right answer . The below did 🙂

index="Application" sourcetype=Servers|eval host=lower(host)|eval started_host="T"|append [inputlookup Mylookup|eval started_host="F"]|stats count(eval(started_host=="T")) as started by host|where started == 0
0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@AdixitSplunk - Did your above comment provide a working solution to your question? If yes and you would like to close out your post, please let me know so I can convert it to an Answer to be accepted. Thanks!

0 Karma

adayton20
Contributor

Try this:

index=Application sourcetype=Servers
| search [|inputlookup yourLookup | fields + host | table host] 
| stats count by host
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...