Splunk Search

How to join multiple child objects of a data model?

sanjay_shrestha
Contributor

We have a situation where we need to join multiple child objects of a data model.

e.g.

 ProjectInformation (Datamodel Object)
                                 _time
                                 host
                                ..........

             ChildOne (Datamodel Child Object)
                                 _time
                                 host
                                ............
                                field1
                                CalculatedField2

             ChildTwo(Datamodel Child Object)
                                 _time
                                 host                               
                                ............
                                 field 1
                                CalculatedField3
             ChildThree(Datamodel Child Object)
                                 _time
                                 host                               
                                ............          
                                CalculatedField3
                                CalculatedField4

We would like to have a result with following fields:

   CalculatedField2; CalculatedField3; CalculatedField4 by field1

where field1 value for ChildThree should be evaluated from ChildTwo.field 1 where ChildTwo.CalculatedField2 = ChildThree.CalculatedField2

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Can you define all of the calculated fields at the top level data model?

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...