I have three CSV files. One is a list of all customers that have logged into my system in the past 24 hours. The second is the master list of all of my customers. I want to list the difference between the two CSV files or, if you prefer, I want to list the customers that have not logged in in the past 24 hours.
CSV file 1: AllCustomers.csv, a static list containing more fields than CSV file 2.
CSV file 2: InactiveCustomers.csv, a static list of all customers and reasons why they might be inactive. This file has two columns, cs_username, Reason
CSV file 3: SynchedCustomers.csv, a list of customers who have logge4din in the past 24 hours. This file has one column, cs_username.
First Search, this returns an accurate list of all active customers into SynchedCustomers.csv
:
sourcetype="iis" cs_uri_stem=*configs.xml
| lookup AllCustomers.csv cs_username
| dedup cs_username
| fields cs_username
| table cs_username
| outputlookup SynchedCustomers.csv
Using a second search all I want to do is to list the two fields in InactiveCustomers.csv if they are NOT found in SynchedCustomers.csv.
This search returns more than the inactive customers:
| inputlookup InactiveCustomers.csv
| search NOT
[search SynchedCustomers.csv | fields cs_username]
What am I doing wrong.
... View more