Splunk Search

Why does tstats works different for root event datasets within the same data model



I have a data model that consists of two root event datasets. Both accelerated using simple SPL.

First dataset I can access using the following


| tstats summariesonly=t count FROM datamodel=model_name 
where nodename=dataset_1 by dataset_1.FieldName


But for the 2nd root event dataset, same format doesn't work. For that, I get events only by referencing the dataset along with the datamodel.


| tstats summariesonly=t count FROM datamodel=model_name.dataset_2 
by dataset_2.FieldName


e.g., the following will not work.


| tstats summariesonly=t count FROM datamodel=model_name 
where nodename=dataset_2 by dataset_2.FieldName



I am trying to understand what causes splunk search to work differently on these datasets when both are at the same level?


~ Abhi

Labels (1)
Tags (2)
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!