I want to use inputlookup to search only a certain set of hosts. These are in a .csv file. I have the query and it's all fine but it's returning results from EVERY host, not just the ones on the list. How can I fix this?
index="wineventlog*" CategoryString="Logon/Logoff Event"
[ inputlookup lars_file_computers_zonder_human_inlog.csv
| return 115 Workstation_Name=$src ]
| table Workstation_Name, src, app, action, user
Just use a lookup as a lookup. this presumes the data the value is src and the field in the lookup is Workstation_Name
index="wineventlog*" CategoryString="Logon/Logoff Event"
| lookup lars_file_computers_zonder_human_inlog.csv Workstation_Name as src OUTPUTNEW Workstation_Name as isFound
| where isnotnull(isFound)