Splunk Search

How to get the Indirect relation using Splunk Search ?



I have a data in which i have the employee name and the manager name.

I want to create a search where if someone select a name ( For Ex: John) it should return records where John is Manager Directly or Indirectly .

In below Example if i select John it should return all 3 records, Joy, Adam and Roy because Adam reports to John and Joy and Roy reports to Adam.

If i select Adam, it should only return 2 records, Joy and Roy.

_timeFirstNameManager Name
08th MarchJoyAdam
07th MarchAdamJohn
06th MarchRoyAdam


Can someone please help, how can i do that ?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...