Splunk Search

Use the '| from datamodel' command when the datamodel is configured as grandparent/parent/child.

rrythi
Loves-to-Learn

I want to query the user dataset using the from datamodel command.
I know how to use nodename in the tstat command.

spl_answer.pngspl_answer_1.png

When I run SPL as shown below, an error appears.

| from datamodel: test_01.evtid.user

If you know how, please reply.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...