Splunk Search

Lookup search - display events which aren't matching

nebel
Communicator

Hi there,

I want to check, which System aren't having forwarders installed.
I am using the 'all_forwarder' search macro which comes with the Deployment Monitor App.
With this macro search I get all Forwarders.

So on the one hand there is a lookup file with all servers in my landscape. On the other hand I have 'all_forwarder' macro which displays all forwarders.

Now I want to check the lookup against the 'all_forwader' macro.
The result should list all servers which are not matching with the Hostlist from the 'all forwarder'

lookup : all_servers
fields with the server host : sourceHost

macro search: all_forwarders
fields with the forwarder hosts : sourceHost

Thanks in advance

Regards

Tags (4)
0 Karma
1 Solution

Ayn
Legend

This should do it, if I understood your question correctly:

| inputlookup all_servers | search NOT [search `all_forwarders` | fields sourceHost]

View solution in original post

0 Karma

Ayn
Legend

This should do it, if I understood your question correctly:

| inputlookup all_servers | search NOT [search `all_forwarders` | fields sourceHost]
0 Karma

nebel
Communicator

thank you very much!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...