Splunk Search

How to combine a search with a data model without the JOIN operator?

christopherwern
New Member

Hi experts,

I try to combine a normal search with a data model without the JOIN operator, because of the slow processing speed and the subsearch result limitation of 50.000 results per search.

I read in the .conf 2016 session by Nick Mealy (https://conf.splunk.com/files/2016/slides/let-stats-sort-them-out-building-complex-result-sets-that-...) that this not possible because the data model command is a generating command. 😞

Does anybody has a solution or face the same problem? I think it is really important to combine a data model and normal searches in a efficient way.

Kind regards,
Christopher

0 Karma
1 Solution

DalJeanis
Legend

There are a number of strategies. The top two are multisearch and append.

MULTISEARCH

| multisearch
    [ search with all streaming distributed commands]
    [ | datamodel search with all streaming distributed commands]
| rename COMMENT as "Commands that are not streaming go here and operate on both subsets."

APPEND

my first search 
| append [| my datamodel search ]
| rename COMMENT as "More commands that operate on both subsets."

View solution in original post

0 Karma

DalJeanis
Legend

There are a number of strategies. The top two are multisearch and append.

MULTISEARCH

| multisearch
    [ search with all streaming distributed commands]
    [ | datamodel search with all streaming distributed commands]
| rename COMMENT as "Commands that are not streaming go here and operate on both subsets."

APPEND

my first search 
| append [| my datamodel search ]
| rename COMMENT as "More commands that operate on both subsets."
0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...