If I perform a search for: eventtype="nix-all-logs" sourcetype=syslog "squirrel" | stats values(SourceIP) as data I get: data Performing an audit check... added file on host hostname_1: f+++++++++++++++++: /opt/folder/logs/2022-Sep-15_file.log changes were found when we performed our check. database containing your updates was created and renamed. We will start using the updated database for file changes. file was changed on host hostname_3: d =.... mc.. .. . : /opt/folder/other_folder file was changed on host hostname_3: f >.... mc..H.. . : /opt/folder/logs/file.log I use SourceIP because when I run: eventtype="nix-all-logs" sourcetype=syslog "squirrel" | stats values() SourceIP is the value that contains the data I want to sort. So far, so good. However, when I include the lookup, it says that there are matches but nothing is returned: eventtype="nix-all-logs" sourcetype=syslog "squirrel" | stats values(SourceIP) as data by host [|inputlookup mylookup.csv | fields MY_Hostname | rename MY_Hostname as host] If run the lookup by itself, it returns a list of each host in the lookup: |inputlookup mylookup.csv | fields MY_Hostname | rename MY_Hostname as host If I can get the 'data' column above to be listed by each host from the above lookup, I think that would do what I need. So, in my example, I should get a table that roughly looks like: hostname_1 Performing an audit check... added file on host hostname_1: f+++++++++++++++++: /opt/folder/logs/2022-Sep-15_file.log changes were found when we performed our check. database containing your updates was created and renamed. We will start using the updated database for file changes. hostname_3 file was changed on host hostname_3: d =.... mc.. .. . : /opt/folder/other_folder file was changed on host hostname_3: f >.... mc..H.. . : /opt/folder/logs/file.log From here, I can then tell the alert to alerts on each result. If you need to see the alerts, what exactly do you need to see to help?
... View more