Splunk Enterprise

Does standard mode federated search not support local data models querying a federated index?

SK1
Loves-to-Learn Everything

We have one standard mode federated index on a remote Splunk cluster. A local data model (model1) has a base search of index="federated:blah" |head10.


Using the search dialog for 'index="federated:blah" | head10', we get 10 results as expected. Running '| from datamodel model1' we get nothing.


Inspecting the search.log, we see the remote Splunk instance being queried when using the search dialog. When calling the data model, there doesn't seem to be any communication out to the remote instance.


Does standard mode federated search not support local data models querying a federated index? Am I doing something wrong?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...