Splunk Search

How to find a host from a list of hosts in a file?

gokulakrishnans
Explorer

I need to refer to a table file which contains a list of servers. Need to check with all the servers like a loop which shows the status as 200-Means success/OtherErrorCode-Unsuccessful.

If any of the servers in the list is having other than 200, then an alert should be triggered.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use a subsearch.

index=foo status!=200 [ | inputlookup serverList.csv ] | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...