Splunk® Enterprise

Data Model and Pivot Tutorial

Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

More Data model and Pivot resources

This tutorial is a brief introduction to building data models and then using them to create pivot visualizations and reports. For more details, refer to the following manuals.

  • Knowledge Manager Manual: Contains a section that shows you how to design and build data models using the Data Model Editor.
  • Pivot Manual: Explains how to use the Pivot Editor to generate tables, charts, and other visualizations of your event data.
  • Dashboards and Visualizations: Contains information on how to build and enhance dashboards and visualizations. This manual also contains a link to the Dashboards Quick Reference Guide, which provides an overview of the most common operations, definitions, and commands that you will use when you create dashboards and visualizations.


We encourage you to investigate the tutorial data, run more searches, and create more dashboards!

To learn more about the Splunk Search Processing Language, see the Search Tutorial.

To learn more about Splunk features and how to use them, see the selection of Education videos and classes.

Last modified on 16 February, 2018
Add pivots to a dashboard  

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters