<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where can I find detailed documentation for using tstats with accelerated data models? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271498#M81738</link>
    <description>&lt;P&gt;Thanks. I had previously scoured through these docs trying dig out tstats idiosyncrasies when using datamodels.&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2016 23:16:30 GMT</pubDate>
    <dc:creator>romedome</dc:creator>
    <dc:date>2016-05-26T23:16:30Z</dc:date>
    <item>
      <title>Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271495#M81735</link>
      <description>&lt;P&gt;I'm starting to use accelerated data models to power some dashboards, but I'm having some issues. For example, after a few days of searching, I only recently found out that to reference fields, I need to use the . format and I'm still not clear on what the use of the "nodename" attribute is.&lt;/P&gt;

&lt;P&gt;My query to the Splunk sages: Where are these and other data model specifics documented?&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 20:52:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271495#M81735</guid>
      <dc:creator>romedome</dc:creator>
      <dc:date>2016-05-26T20:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271496#M81736</link>
      <description>&lt;P&gt;Here's a good answers post with some nice details on using tstats.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/186938/what-is-tstats-and-why-is-so-much-faster-than-stat.html"&gt;https://answers.splunk.com/answers/186938/what-is-tstats-and-why-is-so-much-faster-than-stat.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The nodename refers to a child in a datamodel and allows you to constrain your search in a where clause. So given the sample datamodel included with Splunk, 'Splunk's Internal Server Logs - SAMPLE', as an example:&lt;/P&gt;

&lt;P&gt;&lt;B&gt;server&lt;/B&gt; is the root event.  &lt;B&gt;scheduler&lt;/B&gt; is a child of server. &lt;B&gt;scheduled_reports&lt;/B&gt; is a child of scheduler is a child of server.&lt;/P&gt;

&lt;P&gt;So you'd use nodename like so:&lt;/P&gt;

&lt;PRE&gt;| tstats prestats=true count from datamodel=internal_server where nodename=server.scheduler.scheduled_reports | stats count&lt;/PRE&gt;</description>
      <pubDate>Thu, 26 May 2016 22:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271496#M81736</guid>
      <dc:creator>shaskell_splunk</dc:creator>
      <dc:date>2016-05-26T22:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271497#M81737</link>
      <description>&lt;P&gt;A couple of doc links, if you haven't already gone through them:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Tstats"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Tstats&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Knowledge/Acceleratedatamodels#Query_data_model_acceleration_summaries"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.1/Knowledge/Acceleratedatamodels#Query_data_model_acceleration_summaries&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 26 May 2016 22:30:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271497#M81737</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-05-26T22:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271498#M81738</link>
      <description>&lt;P&gt;Thanks. I had previously scoured through these docs trying dig out tstats idiosyncrasies when using datamodels.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 23:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271498#M81738</guid>
      <dc:creator>romedome</dc:creator>
      <dc:date>2016-05-26T23:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271499#M81739</link>
      <description>&lt;P&gt;Nice, all the details are buried in that post. I had missed them on the first skim. : )&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 23:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271499#M81739</guid>
      <dc:creator>romedome</dc:creator>
      <dc:date>2016-05-26T23:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271500#M81740</link>
      <description>&lt;P&gt;Took me a little bit of time to figure out how to access my data model fields using tstats so I thought I'd share some examples.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# had to use mvexpand to generate a list for a drop-down menu, without it I was getting commas in my dashboard drop-downs
| tstats values(Host_Metadata_Stats.host_env) as host_env from datamodel=Host_Metadata.Host_Metadata_Stats 
| mvexpand host_env 
| table host_env

# avg calculation with 1 second bucket / span
| tstats count from datamodel=Host_Metadata.Host_Metadata_Stats where Host_Metadata_Stats.index="*" Host_Metadata_Stats.host="**" Host_Metadata_Stats.host_app="*" Host_Metadata_Stats.host_env="*" Host_Metadata_Stats.host_server="*" sourcetype="*" by _time span=1s 
| stats avg(count) as eps

# timechart sum
| tstats count from datamodel=Host_Metadata.Host_Metadata_Stats where Host_Metadata_Stats.index="*" Host_Metadata_Stats.host="**" Host_Metadata_Stats.host_app="*" Host_Metadata_Stats.host_env="*" Host_Metadata_Stats.host_server="*" sourcetype="*" by _time index 
| timechart sum(count) as count by index useother=f

# table
| tstats count sum(Host_Metadata_Stats.event_length) as bytes from datamodel=Host_Metadata.Host_Metadata_Stats where Host_Metadata_Stats.index="*" Host_Metadata_Stats.host="**" Host_Metadata_Stats.host_app="*" Host_Metadata_Stats.host_env="*" Host_Metadata_Stats.host_server="*" sourcetype="*" by Host_Metadata_Stats.host_env Host_Metadata_Stats.host_app Host_Metadata_Stats.host_server Host_Metadata_Stats.host Host_Metadata_Stats.host_os Host_Metadata_Stats.index sourcetype source 
| sort host 
| rename Host_Metadata_Stats.host_env as host_env Host_Metadata_Stats.host_app as host_app Host_Metadata_Stats.host as host Host_Metadata_Stats.host_os as host_os Host_Metadata_Stats.index as index Host_Metadata_Stats.host_server as host_server 
| eval mb=round(bytes/1024/1024,2) 
| eval gb=round(bytes/1024/1024/1024,2) 
| sort -bytes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I also found I could get a list of the datamodel field names by using prestats=t in verbose or smart search modes&lt;/P&gt;

&lt;P&gt;| tstats prestats=t count from datamodel=Host_Metadata.Host_Metadata_Stats &lt;BR /&gt;
| table Host_Metadata_Stats* &lt;BR /&gt;
| transpose 1&lt;BR /&gt;
| table column&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:28:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271500#M81740</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-09-29T13:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I find detailed documentation for using tstats with accelerated data models?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271501#M81741</link>
      <description>&lt;P&gt;Consider also the .conf talk I gave last year specifically designed to teach people how to use tstats! &lt;BR /&gt;
Slides: &lt;A href="http://conf.splunk.com/files/2016/slides/how-to-scale-from-raw-to-tstats.pdf"&gt;http://conf.splunk.com/files/2016/slides/how-to-scale-from-raw-to-tstats.pdf&lt;/A&gt;&lt;BR /&gt;
Video: &lt;A href="http://conf.splunk.com/files/2016/recordings/how-to-scale-from-raw-to-tstats.mp4"&gt;http://conf.splunk.com/files/2016/recordings/how-to-scale-from-raw-to-tstats.mp4&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Or go to DC for .conf2017 where I will be re-delivering the same talk (with a few updates)!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2017 13:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Where-can-I-find-detailed-documentation-for-using-tstats-with/m-p/271501#M81741</guid>
      <dc:creator>David</dc:creator>
      <dc:date>2017-06-26T13:10:57Z</dc:date>
    </item>
  </channel>
</rss>

