I have one saved search which returns list of successful job runs e.g
jobname
A
B
C
D
I also have a lookup table with list of all the jobs
jobnames
1
A
2
B
8
C
X
5
I am looking for a way to identify which jobs were not successful. Can we achieve this in SPLUNK ?
Thanks Sekar !
The first part of command I have is a savedsearch which returns table or set of fields, JobName is one of them. JobName is one of the fields.I tried to table or field+ to expose only jobname field. Something like this
| savedsearch "XYZ" NOT [| inputlookup JobnamesAll.csv | fields jobnames]
but no luck so far.
Sure, we can achieve this in Splunk.. Please check -
source="OKjobnames" NOT [| inputlookup JobnamesAll.csv | fields jobbames]