Splunk Search

How to join multiple child objects of a data model?

sanjay_shrestha
Contributor

We have a situation where we need to join multiple child objects of a data model.

e.g.

 ProjectInformation (Datamodel Object)
                                 _time
                                 host
                                ..........

             ChildOne (Datamodel Child Object)
                                 _time
                                 host
                                ............
                                field1
                                CalculatedField2

             ChildTwo(Datamodel Child Object)
                                 _time
                                 host                               
                                ............
                                 field 1
                                CalculatedField3
             ChildThree(Datamodel Child Object)
                                 _time
                                 host                               
                                ............          
                                CalculatedField3
                                CalculatedField4

We would like to have a result with following fields:

   CalculatedField2; CalculatedField3; CalculatedField4 by field1

where field1 value for ChildThree should be evaluated from ChildTwo.field 1 where ChildTwo.CalculatedField2 = ChildThree.CalculatedField2

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Can you define all of the calculated fields at the top level data model?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...