I created a csv file critical.csv with a list of critical assets, and uploaded the lookup table into Splunk. How would I create a query to check to see if these assets have been sending logs to splunk for the past X amount of time. The field name in the lookup is hostname. All of the host are using Splunk universal forwarders.
... View more