![splunk documentation splunk documentation](https://image.slidesharecdn.com/splunklive-introtoenterprisejune10th2015-150615150331-lva1-app6892/95/getting-started-with-splunk-36-638.jpg)
You can also reference saved searches and KV Store lookup definitions. You can reference any dataset listed in the Datasets listing page, such as data model datasets, CSV lookup files, CSV lookup definitions, and table datasets. When you use the from command, you must reference an existing dataset. However, you can use the from command inside the append command. Generating commands use a leading pipe character and should be the first command in a search. It can be either report-generating or event-generating depending on the search or knowledge object that is referenced by the command. The from command is a generating command. That term has been replaced with "data model dataset". In older versions of the Splunk software, the term "data model object" was used. Example: If the data model name is internal_server, and the dataset name is splunkdaccess, specify internal_server.splunkdaccess for the dataset_name. If the name of the dataset contains spaces, enclose the dataset name in quotation marks. If the dataset_type is a data model, the syntax is. Syntax: Description: The name of the dataset that you want to retrieve data from. See About datasets in the Knowledge Manager Manual. You can use from to reference any saved search as a dataset. The savedsearch dataset type is a saved search. The lookup dataset type can be either a CSV lookup or a KV Store lookup. You can create table datasets with the Table Editor if you use Splunk Cloud Platform, or use Splunk Enterprise and have installed the Splunk Datasets Add-on. You create data model datasets with the Data Model Editor. The datamodel dataset type can be either a data model dataset or a table dataset. Valid values are: datamodel, lookup, and savedsearch. Required arguments Syntax: Description: The type of dataset. You can specify a colon ( : ) or a space between and. If you use Splunk Cloud Platform, or use Splunk Enterprise and have installed the Splunk Datasets Add-on, you can also save the search as a table dataset. Save the result as a report, alert, or dashboard panel. Optionally add additional SPL such as lookups, eval expressions, and transforming commands to the search. The from command retrieves data from a dataset, such as a data model dataset, a CSV lookup, a KV Store lookup, a saved search, or a table dataset.ĭesign a search that uses the from command to reference a dataset.