Hi @cwheeler33, if you need to find the hosts in a monitoring perimeter that didin't send logs, you have to create a list of monitored hosts and use it for the control. In few words: create a lookup called e.g. perimeter.csv, the lookup contains at least one field "host", the run a search like this: | metasearch index=_internal
| eval host=lower(host)
| stats count BY host
| append [ search
| inputlookup perimeter.csv
| eval host=lower(host), count=0
| fields host count ]
| stats sum(count) AS total BY host
| where count=0 With this search you check the hosts with Forwarder, if you want also check hosts without forwarder (e.g. network appliance) you have to use a different index, if you want to filter your logs using some field, you cannot use "| metasearch". You can run this search all the times you want, also very frequently (e.g. 5 minutes) to control that you continously have logs. without them you're blind! About the lookup, you have two way to populate it: schedule a search with final outputlookup, manually update it. The first solution is easier and requires less job, but in this way you also have less control on your monitoring perimeter than the second one. Ciao. Giuseppe
... View more