Splunk Search

subtract csv results by metadata source

gnoellbn
Explorer

I'm trying to subtract the list of host contains in my csv file in field "clients_supprimes" to results of host not reporting to Splunk through a search in the metadata.

So normally I would do something like this :

| metadata hosts NOT [search source="/opt/splunk/sources_manuelles/suppression_client.csv" | table clients_supprimes] | ...

But that doesn't work, same thing if I put the search before the first pipe because metadata has to be first in the search.

Would you have any idea ?

Tags (2)
0 Karma

donnymcbride
New Member

What is the typo? What is the correct search that works?

0 Karma

somesoni2
Revered Legend

Try following

|metadata type=hosts index=* | search NOT [search source="/opt/splunk/sources_manuelles/suppression_client.csv" | table clients_supprimes | rename clients_supprimes as host]

Also, if the file suppression_client.csv is static and doesn't change often, consider making it as lookup table file.

donnymcbride
New Member

Please identify typo and the search that is correct and works

0 Karma

somesoni2
Revered Legend

Sorry there was a typo. Corrected it. Its seems to be working fine for me (tested with a csv file of my own).

When you want to run the subsearch standalone, you don't need the keyword "search" to be prefixed. Its only required when using subsearch.

0 Karma

gnoellbn
Explorer

It doesn't seem to work, it seems like it's because of the "[search". It returns "No matching field exist"
If I do a standalone search I need to remove it for it to work but if I do in the subsearch it gives me an error.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...