Knowledge Management

Compare Fields in Data Model vs all other Available fields

admins123
New Member

Hello I'm new to Splunk and I've encountered an issue trying to figure out how to create a search query that will allow me to compare all the fields in a datamodel vs all other fields. Example :I have a datamodel named MyDataModel. This datamodel includes the fields _value, time, _key, location. I would like to create a search that allows me to see all the fields in that particular data model (fields, _value, _key, location) vs all the fields in a specific data set (index=logix_logs) to see if there are any matches. The goal is to see if there are any fields in the datamodel that do not exist in the index=logix_logs data set so that they can be created if need be. Hope that helps. but I'm unsure how to complete the query to give me the information I need. Any help will be greatly appreciated!

Search that brings out all fields in a datamodel:
|datamodel
|spath output=modelName path=modelName
|spath output=foo path=objects{}
|mvexpand foo
|spath input=foo output=objectName path=objectName
|spath input=foo output=foo path=fields{}
|mvexpand foo
|spath input=foo output=fieldName path=fieldName
|spath input=foo output=type path=type
|table modelName,objectName,fieldName,type |search objectName="My DataModel"

Tags (1)
0 Karma

manish_singh_77
Builder

Which fields are you trying to compare? Could you please elaborate?

0 Karma

admins123
New Member

I'm sorry if my question is not very descriptive. Let me attempt to elaborate. I have a datamodel named MyDataModel. This datamodel includes the fields _value, time, _key, location. I would like to create a search that allows me to see all the fields in that particular data model (fields, _value, _key, location) vs all the fields in a specific data set (index=logix_logs) to see if there are any matches. The goal is to see if there are any fields in the datamodel that do not exist in the index=log_logs data set so that they can be created if need be. Hope that helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...