Splunk Search

Unable to use conditions against datamodel

smahoney
Path Finder

Not sure what I am doing wrong.  I have a datamodel with a dataset that I can pivot on a field when using the datamodel explorer.  When I try to use |tstats it does not work.

I get results as expected with 

| tstats count as order_count from datamodel=spc_orders


however if I try and pivot

| tstats count as order_count from datamodel=spc_orders where state="CA"

0 results.

Whats going on here?

Labels (1)
0 Karma
1 Solution

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You need to use proper field name. Prepended by the dataset name.

Don't know your datamodel but as an example, with one of CIM datamodels.

It's not

| tstats count from datamodel=Network_Traffic by src_ip

but

| tstats count from datamodel=Network_Traffic by All_Traffic.src_ip

Of course you need to adjust it to your datamodel.

0 Karma

smahoney
Path Finder

I figured this out.  I had 2 data sets in my model and when I was specifying the datamodel=XXX, I didnt pass a dataset after.  So by default this will assume the first listed dataset and work.  When I was trying to run the query associated with the other dataset it wouldnt.  

Simply adding the dataset name as an argument got it working.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...