Hi @Kksplunker,
try something like this:
index="windows" State="*" service="CB"
| eval host=upper(host)
| stats count BY host
| append [ | inputlookup itsi_entities | rename identifier.values as host | eval host=upper(host), count=0 | fields host count ]
| stats sum(count) AS total BY host
| where total=0
| table total
Ciao.
Giuseppe
.
Hi @Kksplunker,
ok, let me understand:
it's easier, did you tried this?
index="windows" State="*" NOT service="CB"
| ...
Ciao.
Giuseppe
.
Hi @Kksplunker,
sorry but I don't understand your need:
what's your need?
In my opinion you need the first, in which there are the list of all servers with service=CB active that are sending logs and there's the match with the list of all your server from the lookup:
if in your lookup you have more than Windows servers, you have to filter the lookup in the append.
Ciao.
Giuseppe