Thank you, sideview! The groupmember contains the mapping that allows me to group all the datastore by a particular group name. That is the only thing I have to look at over time because Splunk doesn't ingest any information for that entitygroupmembers source past the initial load and only adds a new record when another entity is added. VM and Datastore information is loaded multiple times daily because it is capturing their performance metrics. So, I don't have to look at VM or Datastore for lifetime I just need to do the entitygroupmembers for lifetime so I can map a VM to a Datastore based on the overall group name.
Example:
I select the group "WDMix-SQL-TCL01-WM13-SQL-ALL-Database-Drives" and want to see all the VMs that reside within that group. There is no relationship between VM and EntityGroupMembers. There is a relationship between VM and DataStores. There is also a relationship between EntityGroupMembers and DataStore. I have to Join DataStore and EntityGroupMembers to collect my "lookup" for all datastore within that group_name and output the datastore_name. Then, I have to join the VM to this "lookup" to match the producer_name to the datastore_name. This will provide me the outcome I need.
I hope this is a better explanation.
Thanks again for your help!
I hope this helps explain it a little better.
... View more