Reporting

datamodel - custom command as calculated field

splunk_zen
Builder

We have built a considerable amount of logic using a combination of python and kvstore collections to categorise incoming data

The custom command can be called after the root event by using

| datamodel ... 

or

| tstats ... values()

but I'm not finding a way to call the custom command (a streaming version was also developed) as a calculated field in the datamodel so we can leverage its acceleration without a huge | tstats ... values() chain

Any idea on how to do this ?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...