Reporting

How do you reference a "root search" from a Data Model?

rjthibod
Champion

I have been using Objects and Pivot with much success. In the process of trying to play with the "Root Search" concept, I cannot find documentation on how to actually use the root search. Specifically, how does one include a root search in a Simple XML dashboard? For this example, assume my data model's object ID is "my_dm" and the root search's object id "summary_ids".

Do I reference "summary_ids" in the search field? Do I specify "id='summary_ids'" in a "search" XML field?

Please point me to any documentation or examples that you know of.

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi rjthibod,

You can use the pivot command instead http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Pivot
Just tested it and created a root search called foo in my datamodel called Tutorial which is basically just a * search and I get back some events from the Splunk Unix App and therefore a field called COMMAND. So I can use this to test the pivot command like this:

| pivot Tutorial foo values(COMMAND) AS COMMAND

works like a charm.....

cheers, MuS

View solution in original post

MuS
Legend

Hi rjthibod,

You can use the pivot command instead http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Pivot
Just tested it and created a root search called foo in my datamodel called Tutorial which is basically just a * search and I get back some events from the Splunk Unix App and therefore a field called COMMAND. So I can use this to test the pivot command like this:

| pivot Tutorial foo values(COMMAND) AS COMMAND

works like a charm.....

cheers, MuS

rjthibod
Champion

Thank you! That page is exactly what I was looking for.

MuS
Legend

okay, I'll update my answer so you can accept the correct answer 😉

0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...