I have a lookup file of HostNames
HostName
Host1
Host2
Host3
Host4
Host5
I would like to create a search to include events that are only from these hostnames listed in my lookup file. How do I do this.? Which "host" field matches the "Hostname" field in my lookup file.
An example would be, I am looking for which of these host that are sending windows security logs or not. I know all these systems should be, but some are not, and I want to know which ones are and which one are not using the lookup file.
... View more