Reporting

Host is not available in Data Model (Web), but displays when using pivot from same Datamodel

gibronda
Explorer

NO RESULTS from the following:

| tstats summariesonly=false  count FROM datamodel=Web WHERE (Web.action=*block*)  by Web.action, Web.host, Web.src, Web.dest |rename Web.* as *|table action, host, src, dest

Results from this:

| tstats summariesonly=false  count FROM datamodel=Web WHERE (Web.action=*block*)  by Web.action, Web.src, Web.dest |rename Web.* as *|table action,  src, dest

Creating Pivot from the same Web datamodel displays host results:

| pivot Web Web count(Web) AS "Count of Web" SPLITROW dest AS Dest SPLITROW src AS Src SPLITROW host AS Host FILTER action is "block*" SORT 1000 dest ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1

We need the results from the datamodel to append to other results. Any assistance would be appreciated.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...