Splunk Search

How to join multiple child objects of a data model?

sanjay_shrestha
Contributor

We have a situation where we need to join multiple child objects of a data model.

e.g.

 ProjectInformation (Datamodel Object)
                                 _time
                                 host
                                ..........

             ChildOne (Datamodel Child Object)
                                 _time
                                 host
                                ............
                                field1
                                CalculatedField2

             ChildTwo(Datamodel Child Object)
                                 _time
                                 host                               
                                ............
                                 field 1
                                CalculatedField3
             ChildThree(Datamodel Child Object)
                                 _time
                                 host                               
                                ............          
                                CalculatedField3
                                CalculatedField4

We would like to have a result with following fields:

   CalculatedField2; CalculatedField3; CalculatedField4 by field1

where field1 value for ChildThree should be evaluated from ChildTwo.field 1 where ChildTwo.CalculatedField2 = ChildThree.CalculatedField2

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Can you define all of the calculated fields at the top level data model?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...