I need to find new added hosts using lookup files.
The solutions in blog didn't work for me.
I will create a lookup file with all my hosts. ( I did)
If any new host will be added , it will be displayed.
Any help will be appreciated.
Hi @gabrieltrust ,
if you have a lookup (called e.g. perimeter.csv) with at least one field (host), you can run something like this:
| tstats count WHERE index=* NOT [ | inputlookup perimeter.csv | fields host ] BY host
Ciao.
giuseppe
Hi @gabrieltrust ,
if you have a lookup (called e.g. perimeter.csv) with at least one field (host), you can run something like this:
| tstats count WHERE index=* NOT [ | inputlookup perimeter.csv | fields host ] BY host
Ciao.
giuseppe
Works Great! Thank you
Get your list of unique hosts, append your list of unique hosts from the lookup file twice, use stats to count by host, where the count is only 1, the host is not in the lookup file, where it is 2 it is only in the lookup file, where it is 3, it is in both the searched events and the lookup file.