Splunk Search

How to combine a search with a data model without the JOIN operator?

christopherwern
New Member

Hi experts,

I try to combine a normal search with a data model without the JOIN operator, because of the slow processing speed and the subsearch result limitation of 50.000 results per search.

I read in the .conf 2016 session by Nick Mealy (https://conf.splunk.com/files/2016/slides/let-stats-sort-them-out-building-complex-result-sets-that-...) that this not possible because the data model command is a generating command. 😞

Does anybody has a solution or face the same problem? I think it is really important to combine a data model and normal searches in a efficient way.

Kind regards,
Christopher

0 Karma
1 Solution

DalJeanis
Legend

There are a number of strategies. The top two are multisearch and append.

MULTISEARCH

| multisearch
    [ search with all streaming distributed commands]
    [ | datamodel search with all streaming distributed commands]
| rename COMMENT as "Commands that are not streaming go here and operate on both subsets."

APPEND

my first search 
| append [| my datamodel search ]
| rename COMMENT as "More commands that operate on both subsets."

View solution in original post

0 Karma

DalJeanis
Legend

There are a number of strategies. The top two are multisearch and append.

MULTISEARCH

| multisearch
    [ search with all streaming distributed commands]
    [ | datamodel search with all streaming distributed commands]
| rename COMMENT as "Commands that are not streaming go here and operate on both subsets."

APPEND

my first search 
| append [| my datamodel search ]
| rename COMMENT as "More commands that operate on both subsets."
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...