Splunk Search

Unable to use conditions against datamodel

smahoney
Path Finder

Not sure what I am doing wrong.  I have a datamodel with a dataset that I can pivot on a field when using the datamodel explorer.  When I try to use |tstats it does not work.

I get results as expected with 

| tstats count as order_count from datamodel=spc_orders


however if I try and pivot

| tstats count as order_count from datamodel=spc_orders where state="CA"

0 results.

Whats going on here?

Labels (1)
0 Karma
1 Solution

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You need to use proper field name. Prepended by the dataset name.

Don't know your datamodel but as an example, with one of CIM datamodels.

It's not

| tstats count from datamodel=Network_Traffic by src_ip

but

| tstats count from datamodel=Network_Traffic by All_Traffic.src_ip

Of course you need to adjust it to your datamodel.

0 Karma

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...