I prepared csv to inputlookup to compare the Splunk logs. adhoc.csv // Account, test01,etc.... test02,etc.... // my Query index=msad sourcetype=msad [| inputlookup adhoc.csv | fields Account] Searching Period: Last 24 hours Cross check adhoc.csv match the searching logs. For those account did not perform any authentation which logs stored at index=msad, during search period, then show zero values.
... View more