You show me tip. I have added to csv like this
nr,group_name,desc
1,("Domain Admins"),super
2,("Domain Users"),standard
and quates are in search
normalizedSearch litsearch (index=* sourcetype="WinEventLog:Security" ("Domain Admins" OR "Domain Users")) | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"
Events returns exactly as from
index=* sourcetype="WinEventLog:Security" (("Domain Admins") OR ("Domain Users"))
only one moment that search is going long, but for start it is OK.
Thank you for advice!
Final search looks:
index=* sourcetype="WinEventLog:Security" [| inputlookup group_list.csv |
return 10 $group_name]
CSV
nr,group_name,desc
1,("Domain Admins"),super
2,("Domain Users"),standard
... View more