Hi,
I use the basic query below in order to collect the model of a host (workstation)
index="xx" sourcetype="WMI:Model" | table host Model
In parallel, I have a CSV file called "cmdb" where there is a field called "HOSTNAME", which refers to the field "host" in my search
I want to match these 2 fields (host and HOSTNAME) in order to collect in a same table the host, the Model and other fields of my CSV file like CLIENT_USER COUNTRY STATUS ROOM SITE & TOWN
Could you help me please??
Try this: index="xx" sourcetype="WMI:Model" |fields host Model | lookup cmdb HOSTNAME as host OUTPUTNEW | table *
Try this: index="xx" sourcetype="WMI:Model" |fields host Model | lookup cmdb HOSTNAME as host OUTPUTNEW | table *
I know this answer is pretty old but, does this kind of lookup match command work within tstats or how would I need to re arrange it?
perfect thanks