<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to solve the Accelerated Data Model Search Problem in Splunk Common Information Model (CIM)? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372329#M45048</link>
    <description>&lt;P&gt;can confirm, data model acceleration is at 100%.  sourcetype=* was chosen as sourcetype=bluecoat wasn't working and wanted to see if any of the other sourcetypes were present in the search results.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 16:03:54 GMT</pubDate>
    <dc:creator>MikeElliott</dc:creator>
    <dc:date>2018-03-22T16:03:54Z</dc:date>
    <item>
      <title>How to solve the Accelerated Data Model Search Problem in Splunk Common Information Model (CIM)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372327#M45046</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have recently mapped new sourcetypes to the Web data model, however, when searching using tstats, none of the new sourcetypes are returned in the search results.  &lt;/P&gt;

&lt;P&gt;When I run the below search, I can see that data from my websense, squid and bluecoat proxies are present in the data model&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| datamodel Web Web search | search * | stats count by index, sourcetype | sort -count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when attempting to search the data model using tstats, only websense and squid show up in the search results.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats summariesonly=t prestats=f count from datamodel=Web.Web WHERE sourcetype=* BY sourcetype Web.src Web.site Web.dest Web.url | dedup sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Does anyone have any ideas what has gone wrong?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:15:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372327#M45046</guid>
      <dc:creator>MikeElliott</dc:creator>
      <dc:date>2018-03-22T14:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve the Accelerated Data Model Search Problem in Splunk Common Information Model (CIM)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372328#M45047</link>
      <description>&lt;P&gt;is the acceleration completed? and if your are doing by sourcetype why sourcetype=*, is sourcetype field has null values?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:22:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372328#M45047</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-22T14:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve the Accelerated Data Model Search Problem in Splunk Common Information Model (CIM)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372329#M45048</link>
      <description>&lt;P&gt;can confirm, data model acceleration is at 100%.  sourcetype=* was chosen as sourcetype=bluecoat wasn't working and wanted to see if any of the other sourcetypes were present in the search results.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 16:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372329#M45048</guid>
      <dc:creator>MikeElliott</dc:creator>
      <dc:date>2018-03-22T16:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve the Accelerated Data Model Search Problem in Splunk Common Information Model (CIM)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372330#M45049</link>
      <description>&lt;P&gt;I had this issue &lt;/P&gt;

&lt;P&gt;A data model names Web that includes my WAF source type &lt;BR /&gt;
I created another DM named after my WAF, this caused my WAF not to show in the results as a sourcetype  when querying the Web DM &lt;/P&gt;

&lt;P&gt;So i removed the created DM and it worked again &lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 15:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-solve-the-Accelerated-Data-Model-Search-Problem-in-Splunk/m-p/372330#M45049</guid>
      <dc:creator>aamer86</dc:creator>
      <dc:date>2019-01-21T15:29:35Z</dc:date>
    </item>
  </channel>
</rss>

