Reporting

Attributes on Pivot Tables

ruisantos
Path Finder

I have a number of sources where I extract fields using CSV on report level.
Do pivots and datamodels only work with fields extract at transform level?

0 Karma
1 Solution

sowings
Splunk Employee
Splunk Employee

You can employ lookups to define attributes in a data model.

View solution in original post

0 Karma

sowings
Splunk Employee
Splunk Employee

You can employ lookups to define attributes in a data model.

0 Karma

sowings
Splunk Employee
Splunk Employee

Ah, I see. I would tackle this problem by configuring the lookup as an automatic lookup (if it isn't already) and then define the attributes from the "auto-extracted" list in your base search. That way, the base search of the data model calls out the values from the lookup table as required (or optional), so that they're available to pivot on.

0 Karma

ruisantos
Path Finder

lookups are diferent from attributes.

According the documentation attributes are the set of fields that the data model represents. They provide the fields that Pivot users work with to define and generate a pivot report. They can also be used to set up the definition of other data model attributes.
Object attributes are inherited from parent objects.

and this is my problem, I'm trying to create a pivot table where I have already a number of fields extracted (at the report level) but they don't seem to show on the data model.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...