Splunk Search

Why does tstats works different for root event datasets within the same data model

att35
Builder

Hi.

I have a data model that consists of two root event datasets. Both accelerated using simple SPL.

First dataset I can access using the following

 

| tstats summariesonly=t count FROM datamodel=model_name 
where nodename=dataset_1 by dataset_1.FieldName

 

But for the 2nd root event dataset, same format doesn't work. For that, I get events only by referencing the dataset along with the datamodel.

 

| tstats summariesonly=t count FROM datamodel=model_name.dataset_2 
by dataset_2.FieldName

 

e.g., the following will not work.

 

| tstats summariesonly=t count FROM datamodel=model_name 
where nodename=dataset_2 by dataset_2.FieldName

 

 

I am trying to understand what causes splunk search to work differently on these datasets when both are at the same level?

Thanks,

~ Abhi

Labels (1)
Tags (2)

Yaron_Eilat
Engager

I am very new to Splunk but I just encountered the explanation for this in a course 🙂

When no Dataset is specified in the From clause, Splunk assumes the first root Dataset is addressed.

When you want to address any root Dataset other than the first one, you must specify it explicitly.

Therefore, it is best practice to ignore the fact that Splunk assumes the first root Dataset and specify it in every use even if Splunk allows you to save that little bit of typing 😉

 

 

| tstats summariesonly=t count FROM datamodel=model_name.dataset_1 
where nodename=dataset_1 by dataset_1.FieldName

 

 

 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...