Splunk Search

Unable to use conditions against datamodel

smahoney
Path Finder

Not sure what I am doing wrong.  I have a datamodel with a dataset that I can pivot on a field when using the datamodel explorer.  When I try to use |tstats it does not work.

I get results as expected with 

| tstats count as order_count from datamodel=spc_orders


however if I try and pivot

| tstats count as order_count from datamodel=spc_orders where state="CA"

0 results.

Whats going on here?

Labels (1)
0 Karma
1 Solution

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You need to use proper field name. Prepended by the dataset name.

Don't know your datamodel but as an example, with one of CIM datamodels.

It's not

| tstats count from datamodel=Network_Traffic by src_ip

but

| tstats count from datamodel=Network_Traffic by All_Traffic.src_ip

Of course you need to adjust it to your datamodel.

0 Karma

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...