Hi mkamal18,
if in your lookup there's another field with values for each host (e.g. "description") try something like this
| metasearch index=my_index
| dedup host
| lookup mylookup.csv host OUTPUT description
| eval Status=if(description=*,""OK","KO")
| table host Status
if in your lookup there isn't any additional field, try something like this:
| metasearch index=my_index [ | inputlookup mylookup.csv | dedup host | fields host ]
| dedup host
| eval Status="OK"
| append [
| metasearch index=my_index NOT [ | inputlookup mylookup.csv | dedup host | fields host ]
| dedup host
| eval Status="KO"
]
| table host Status
In both cases, beware to the case of the host.
Bye.
Giuseppe
Hi mkamal18,
if in your lookup there's another field with values for each host (e.g. "description") try something like this
| metasearch index=my_index
| dedup host
| lookup mylookup.csv host OUTPUT description
| eval Status=if(description=*,""OK","KO")
| table host Status
if in your lookup there isn't any additional field, try something like this:
| metasearch index=my_index [ | inputlookup mylookup.csv | dedup host | fields host ]
| dedup host
| eval Status="OK"
| append [
| metasearch index=my_index NOT [ | inputlookup mylookup.csv | dedup host | fields host ]
| dedup host
| eval Status="KO"
]
| table host Status
In both cases, beware to the case of the host.
Bye.
Giuseppe
I know this was awhile ago, but how would one go about doing this to state if the host is just in the search results, only in the lookup, or in both?
Hello,
Thank you Giuseppe, It was really helpful. 🙂