Let's assume you have your list of possible values in the lookup named message_id_lookup, your events sourceytpe is named messages and you have the message_id field in your events ant the lookup file looks like that:
message_id
value1
value2
value3
value4
value5
value6
Then, you can use following search:
| inputlookup message_id_lookup
| stats count by message_id
| eval count=count-1
| append [search sourcetype=messages | stats count by message_id ]
| stats sum(count) by message_id
To raise an alert if the message_id doesn't appear in your events you can define the saved search:
| inputlookup message_id_lookup
| search NOT [search sourcetype=messages | dedup message_id | fields message_id]
Then build the alert on this search.
... View more