Home
Join the Community
Welcome Center
Welcome Center
Join Slack
Be a Splunk Champion
SplunkTrust
Splunk MVP
Become a User Group Leader
Splunk Love
Share a Tip
Find Answers
Splunk Administration
Getting Data In
Deployment Architecture
Monitoring Splunk
Using Splunk
Splunk Search
Dashboards & Visualizations
Splunk Products
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud Platform
Splunk Observability Cloud
Splunk AppDynamics
Splunk SOAR
Apps & Add-ons
All Apps and Add-ons
Splunk Development
Events
User Groups
Tech Talks: Technical Deep Dives
Office Hours: Ask the Experts
From Data to Insight: The Splunk Dashboard Contest
Dashboard Contest Terms and Conditions
Blogs
Community Blog
Product News & Announcements
Training & Certification Blog
Learning
Learning Paths
Training & Certification
Training + Certification Discussions
AppDynamics Knowledge Base
Best of conf
Resources
.conf25
Splunkbase
Developers
Documentation
Splunk Ideas
Splunk Events
Voice of Customer
Sign In
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Show
only
|
Search instead for
Did you mean:
×
Join the Conversation
Without signing in, you're just watching from the sidelines.
Sign in or Register
to connect, share, and be part of the Splunk Community.
Ask a Question
Find Answers
:
About jlh3dz
jlh3dz
New Member
Member since:
06-20-2017
06-05-2020
Community Statistics
Posts
2
Solutions
0
Karma Given
0
Karma Received
0
Member Since
06-20-2017
Activity Feed
Posted
Re: How to create an alert when a new forwarder is added to deployment server?
on
Getting Data In
.
06-20-2017
11:52 AM
Posted
Re: How to create an alert when a new forwarder is added to deployment server?
on
Getting Data In
.
06-20-2017
11:01 AM
Topics I've Started
No posts to display.
View All
Latest Contributions by jlh3dz
Topics jlh3dz has Participated In
Latest Contributions by jlh3dz
Re: How to create an alert when a new forwarder is...
by
jlh3dz
in
Getting Data In
06-20-2017
11:52 AM
06-20-2017
11:52 AM
I found the answer. "search" is missing. Use | tstats count where index = _* by host | search NOT [inputlookup forwarders.csv | fields+ host] | stats values(host) AS new_hosts
... View more
Re: How to create an alert when a new forwarder is...
by
jlh3dz
in
Getting Data In
06-20-2017
11:01 AM
06-20-2017
11:01 AM
I get the same error, "Search Factory: Unknown search command 'not'."
... View more
Contact Me
Online Status
Offline
Date Last Visited
06-05-2020
02:03 AM