Splunk Search

How to get the Indirect relation using Splunk Search ?

shivamagrawa
Explorer

Hello,

I have a data in which i have the employee name and the manager name.

I want to create a search where if someone select a name ( For Ex: John) it should return records where John is Manager Directly or Indirectly .

In below Example if i select John it should return all 3 records, Joy, Adam and Roy because Adam reports to John and Joy and Roy reports to Adam.

If i select Adam, it should only return 2 records, Joy and Roy.

_timeFirstNameManager Name
08th MarchJoyAdam
07th MarchAdamJohn
06th MarchRoyAdam

 

Can someone please help, how can i do that ?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...