Searching datasets using the pivot command

The Splunk pivot command allows for Pivot-based searching of datasets mapped by data models directly from the Splunk search interface. The command differs from the datamodel and from commands we looked at earlier in this chapter, as it can take advantage of performance gains offered by accelerated data models, whereas datamodel or from cannot. However, the from command is more extensible, as it allows for regular Splunk search syntax following the command, whereas pivot uses a specialized search syntax that is very different from the regular search syntax.

When you use the Pivot tool interface to manipulate the underlying dataset, Splunk writes a search using the pivot command behind the scenes. ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.