Reporting

Attributes on Pivot Tables

ruisantos
Path Finder

I have a number of sources where I extract fields using CSV on report level.
Do pivots and datamodels only work with fields extract at transform level?

0 Karma
1 Solution

sowings
Splunk Employee
Splunk Employee

You can employ lookups to define attributes in a data model.

View solution in original post

0 Karma

sowings
Splunk Employee
Splunk Employee

You can employ lookups to define attributes in a data model.

0 Karma

sowings
Splunk Employee
Splunk Employee

Ah, I see. I would tackle this problem by configuring the lookup as an automatic lookup (if it isn't already) and then define the attributes from the "auto-extracted" list in your base search. That way, the base search of the data model calls out the values from the lookup table as required (or optional), so that they're available to pivot on.

0 Karma

ruisantos
Path Finder

lookups are diferent from attributes.

According the documentation attributes are the set of fields that the data model represents. They provide the fields that Pivot users work with to define and generate a pivot report. They can also be used to set up the definition of other data model attributes.
Object attributes are inherited from parent objects.

and this is my problem, I'm trying to create a pivot table where I have already a number of fields extracted (at the report level) but they don't seem to show on the data model.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...