<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data model hierarchy disrupting data ? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Data-model-hierarchy-disrupting-data/m-p/428630#M7022</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am trying to use data model as I have large dataset to accelerate dashboards I use. &lt;BR /&gt;
So I have 3 lvl hierarchy where I filter each subsequent data level by constraint.  &lt;/P&gt;

&lt;P&gt;To be precise first level filters by index, second by  source name and third by further filtering the sources. &lt;/P&gt;

&lt;P&gt;The problem is  that at this third level I am not getting data accordingly to last condition. &lt;/P&gt;

&lt;P&gt;example: lvl 1  index sql &lt;BR /&gt;
lvl2 source:tech0*&lt;BR /&gt;
lvl3 source:tech02&lt;/P&gt;

&lt;P&gt;so at lvl3 I should be able to see field FreeSpace_in_MB and Drive but they are missing. It almost seems like splunk isnt able to extract all the fields at once an then divide them correctly.&lt;/P&gt;

&lt;P&gt;in fact in all levels I am getting the same fields. Are these fields not supposed to be distributed to respective datasets  by constraint I set ? &lt;/P&gt;

&lt;P&gt;Thank you for answer&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:37:01 GMT</pubDate>
    <dc:creator>danieldurkovic</dc:creator>
    <dc:date>2020-09-30T01:37:01Z</dc:date>
    <item>
      <title>Data model hierarchy disrupting data ?</title>
      <link>https://community.splunk.com/t5/Reporting/Data-model-hierarchy-disrupting-data/m-p/428630#M7022</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am trying to use data model as I have large dataset to accelerate dashboards I use. &lt;BR /&gt;
So I have 3 lvl hierarchy where I filter each subsequent data level by constraint.  &lt;/P&gt;

&lt;P&gt;To be precise first level filters by index, second by  source name and third by further filtering the sources. &lt;/P&gt;

&lt;P&gt;The problem is  that at this third level I am not getting data accordingly to last condition. &lt;/P&gt;

&lt;P&gt;example: lvl 1  index sql &lt;BR /&gt;
lvl2 source:tech0*&lt;BR /&gt;
lvl3 source:tech02&lt;/P&gt;

&lt;P&gt;so at lvl3 I should be able to see field FreeSpace_in_MB and Drive but they are missing. It almost seems like splunk isnt able to extract all the fields at once an then divide them correctly.&lt;/P&gt;

&lt;P&gt;in fact in all levels I am getting the same fields. Are these fields not supposed to be distributed to respective datasets  by constraint I set ? &lt;/P&gt;

&lt;P&gt;Thank you for answer&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-model-hierarchy-disrupting-data/m-p/428630#M7022</guid>
      <dc:creator>danieldurkovic</dc:creator>
      <dc:date>2020-09-30T01:37:01Z</dc:date>
    </item>
  </channel>
</rss>

