Splunk Search

Is it possible to use where command in Data Model?

wilhelmF
Path Finder

I have datamodel and I want to create a child datamodel based on a field comparison. In a normal search I would use a where command but in the constraints I only can use a search command. My question is there a way to do it without an eval expression in a field?

0 Karma

Yunagi
Communicator

How about you create a calculated field under Settings/Fields? Something like:

Name: match
Eval expression: if(field1==field2,"yes","no")

Then you can create your child datamodel based on the constraint:

match="yes"

DalJeanis
Legend

@Yunagi - This is a correct way to go about this, although it does not meet OP's requirement of not having an eval in a field.

@wilhelmf - Not sure what your reason for not wanting the eval field. If you are just worrying about complicating the data model from a user's point of view, then you can hide the calculated field.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...