I have a lookup file with indexes in it, I want a query i need the eventcount of the indexes mentioned in the lookup table for 24 hrs
This should get you going in the right direction.
| tstats count where [|inputlookup indexes.csv | fields index | format] by index
hi @vijaysri
https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Eventcount