I have a dataset to visualize my organization in Splunk. When I search for Org=CDO, I get all the direct reports under the CDO, which include positions like CSO and CIO. Under each of these positions, there are many VPs, and under each VP, there are many directors. How can I retrieve the results for the entire hierarchy under the CDO using Splunk? We have a field named Org and another field name job_title
When I search Org=CDO I get only direct reports of CDO, no other value in the raw event to extract.
any help would be appreciated
Try https://github.com/whackyhack/Splunk-org-chart. (Play with the dashboard to find who's the big boss:-)