I am familiar with Pivot tables under Microsoft Excel and would like to recreate Pivot tables in Splunk, but don't know where to begin.
Splunk requires data models, but how does a data model match my input file and why does Splunk
needs it to create a Pivot Table?
I see only two sample data models under Pivot. How can I add data models? Does Pivot work like in Excel?
I would appreciate any help. Thanks!
I have seen the pivot manual but how can you go about it if the Buttercup Games Sales data model does not exist? There are only two audit data models: Internal Audit Logs and Internal Server Logs Samples.
Is there a step by step example or video in creating just Data Model than the reference to Data Model and Pivot Tutorial? The reference seems to be written for an advance Splunk user. We need the Data Model 101 course. Thanks!
There is a Pivot video I found: https://www.youtube.com/watch?v=MdjDrDTXYWQ.
The tutorial is pretty straightforward, though: it walks you through downloading the sample data, getting it in, and creating the data model. The only extra complexity is that it includes a lookup table to enrich the data.
I am stuck on Add lookup attributes from lookup tables but the prices_lookup under Add Attributes with a Lookup is missing and only shows the dnslookup. Did I miss a step?
I tried but I don't know where the prices.csv resides. It is not in the tutorialdata.zip file downloaded in the first step. Ok I found finally found it. I missed a step. Thanks!
Even though I am not done with the whole tutorial, I want to thank you for your answers! I think it would help if the tutorial would come with a cheatsheet. Thanks again Chris for your patience!