Hi Giuseppe,
Search 1 : index=server_info platform=redhat message="SYSINFO*" host="*"
| dedup host | table host Window kernel version
results 29467
Search 2 : | inputlookup Host-Q3.csv | table host Window
Result: 15679
Search combined : index=cba_chef platform=redhat message="SYSINFO*" host="*"
| lookup Host-Q3.csv host OUTPUT Window | where Window != " " | dedup host |
table host Window kernel version
results 3599
i dont know why the results are not complete, ideally combined searc should give 15000 events but it doesn't , i have tried all the solutions listed below but same results .
is there any other way to to search only limited events/host from the whole load of events.
... View more