Splunk Search

Unable to use conditions against datamodel

smahoney
Path Finder

Not sure what I am doing wrong.  I have a datamodel with a dataset that I can pivot on a field when using the datamodel explorer.  When I try to use |tstats it does not work.

I get results as expected with 

| tstats count as order_count from datamodel=spc_orders


however if I try and pivot

| tstats count as order_count from datamodel=spc_orders where state="CA"

0 results.

Whats going on here?

Labels (1)
0 Karma
1 Solution

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You need to use proper field name. Prepended by the dataset name.

Don't know your datamodel but as an example, with one of CIM datamodels.

It's not

| tstats count from datamodel=Network_Traffic by src_ip

but

| tstats count from datamodel=Network_Traffic by All_Traffic.src_ip

Of course you need to adjust it to your datamodel.

0 Karma

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...