Splunk Search

Use the '| from datamodel' command when the datamodel is configured as grandparent/parent/child.

rrythi
Loves-to-Learn

I want to query the user dataset using the from datamodel command.
I know how to use nodename in the tstat command.

spl_answer.pngspl_answer_1.png

When I run SPL as shown below, an error appears.

| from datamodel: test_01.evtid.user

If you know how, please reply.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...