Trying to find any DeviceId field values that appear in the ActiveSync search but NOT in the MobileIron search.
What is the best way to do this?
ActiveSync search:
index=msexchange source=otl_activesyncinventory
|dedup SamAccountName, DeviceId
|table companyOu, SamAccountName, "AD Account Enabled", DeviceId
MobileIron search:
index=msexchange source=otl_mobileiron
| table, DeviceId, MailboxId, Status
This will give you the list of DeviceId values that only appear in the ActiveSync search.
index=msexchange (source=otl_activesyncinventory OR source=otl_mobileiron)
| stats count by source DeviceId
| eventstats dc(source) as dc by DeviceId
| search dc=1 source=otl_activesyncinventory
| fields DeviceId
You can then use that search in the first step of you first search to get the full table of results you are looking for
index=msexchange source=otl_activesyncinventory
[
search index=msexchange (source=otl_activesyncinventory OR source=otl_mobileiron)
| stats count by source DeviceId
| eventstats dc(source) as dc by DeviceId
| search dc=1 source=otl_activesyncinventory
| fields DeviceId
]
|dedup SamAccountName, DeviceId
|table companyOu, SamAccountName, "AD Account Enabled", DeviceId
This will give you the list of DeviceId values that only appear in the ActiveSync search.
index=msexchange (source=otl_activesyncinventory OR source=otl_mobileiron)
| stats count by source DeviceId
| eventstats dc(source) as dc by DeviceId
| search dc=1 source=otl_activesyncinventory
| fields DeviceId
You can then use that search in the first step of you first search to get the full table of results you are looking for
index=msexchange source=otl_activesyncinventory
[
search index=msexchange (source=otl_activesyncinventory OR source=otl_mobileiron)
| stats count by source DeviceId
| eventstats dc(source) as dc by DeviceId
| search dc=1 source=otl_activesyncinventory
| fields DeviceId
]
|dedup SamAccountName, DeviceId
|table companyOu, SamAccountName, "AD Account Enabled", DeviceId