Reporting

Attributes on Pivot Tables

ruisantos
Path Finder

I have a number of sources where I extract fields using CSV on report level.
Do pivots and datamodels only work with fields extract at transform level?

0 Karma
1 Solution

sowings
Splunk Employee
Splunk Employee

You can employ lookups to define attributes in a data model.

View solution in original post

0 Karma

sowings
Splunk Employee
Splunk Employee

You can employ lookups to define attributes in a data model.

0 Karma

sowings
Splunk Employee
Splunk Employee

Ah, I see. I would tackle this problem by configuring the lookup as an automatic lookup (if it isn't already) and then define the attributes from the "auto-extracted" list in your base search. That way, the base search of the data model calls out the values from the lookup table as required (or optional), so that they're available to pivot on.

0 Karma

ruisantos
Path Finder

lookups are diferent from attributes.

According the documentation attributes are the set of fields that the data model represents. They provide the fields that Pivot users work with to define and generate a pivot report. They can also be used to set up the definition of other data model attributes.
Object attributes are inherited from parent objects.

and this is my problem, I'm trying to create a pivot table where I have already a number of fields extracted (at the report level) but they don't seem to show on the data model.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...