You can do a join, I use it to compare hosts in AD to Splunk for missing ones
| ldapsearch search="(&(objectClass=user)(&(objectClass=computer)))"
| table cn lastLogon description
| join type=left cn [
| inputlookup dmc_forwarder_assets | search os=Windows | table hostname, status, arch, last_connected
| rename hostname AS cn]
| eval epoch1day_ago=relative_time(now(), "-1d@d" )
| where (last_connected < epoch1day_ago OR isnull(last_connected) )
| eval last_connected=strftime('last_connected', "%c")
| table cn,lastLogon,description,arch,last_connected,status
... View more