<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data model acceleration status: Building in Other Usage</title>
    <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/661217#M951</link>
    <description>&lt;P&gt;Solution in my case was a field marked as required which was missing in the data - after adding it to the data again the issue was solved.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 15:20:31 GMT</pubDate>
    <dc:creator>_Tom</dc:creator>
    <dc:date>2023-10-18T15:20:31Z</dc:date>
    <item>
      <title>Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297642#M943</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am new to Data models and accelerations, too. I am trying to parse log for a data model and ES. The log parsing is moving now, but far from the final solution, I can search by Data model/Pivot.&lt;/P&gt;

&lt;P&gt;I checked the Enterprise Security dashboard, but it does not show anything that can be linked to this logs. I executed the dashboards searches manually, still shows no event matched. (| tstats...) Then I checked Data model acceleration status:&lt;BR /&gt;
    ACCELERATION&lt;BR /&gt;
    Rebuild Update  Edit&lt;BR /&gt;&lt;BR /&gt;
    Status    Building &lt;BR /&gt;
    Access Count    0. &lt;BR /&gt;
    Last Access: -&lt;BR /&gt;&lt;BR /&gt;
    Size on Disk    0 B &lt;BR /&gt;
    Summary Range    31536000 second(s) &lt;BR /&gt;
    Buckets    0&lt;BR /&gt;&lt;BR /&gt;
    Updated    1/1/70 1:00:00.000 AM    &lt;/P&gt;

&lt;P&gt;What couse the problem, how can I debug and fix it?&lt;BR /&gt;
This is the Malware data model, there are events with tag malware and attack. There are events with some action and dest fields to.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 12:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297642#M943</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-01-08T12:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297643#M944</link>
      <description>&lt;P&gt;check this&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/149645/how-to-tell-if-accelerated-data-model-is-still-rebuilding.html"&gt;https://answers.splunk.com/answers/149645/how-to-tell-if-accelerated-data-model-is-still-rebuilding.html&lt;/A&gt;&lt;BR /&gt;
it may help you&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 12:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297643#M944</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-08T12:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297644#M945</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thx, I already checked the menu/action item under Search &amp;amp; Reporting/Datasets/Malware,  Explore/"Visualize with Pivot" and "Investigate in Search". Both show results. (This is the "View Events"?)&lt;BR /&gt;
Permissions also look good (scheduler logs).&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 15:31:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297644#M945</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-01-08T15:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297645#M946</link>
      <description>&lt;P&gt;Hi, a little update:&lt;/P&gt;

&lt;P&gt;I built a Linux test system instead of Windows-based. Data model acceleration now 100%, but size still 0B.&lt;/P&gt;

&lt;P&gt;Running tstats searches:&lt;BR /&gt;
- with summariesonly=t: no result&lt;BR /&gt;
- with summariesonly=f: I've received a valid result.&lt;/P&gt;

&lt;P&gt;I far as I can see, the searches of the Data model acceleration running with success,&lt;/P&gt;

&lt;P&gt;Any suggestion?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 10:18:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297645#M946</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-01-11T10:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297646#M947</link>
      <description>&lt;P&gt;summariesonly&lt;BR /&gt;
Syntax: summariesonly=&lt;BR /&gt;
Description: Only applies when selecting from an accelerated data model. When false, generates results from both summarized data and data that is not summarized. For data not summarized as TSIDX data, the full search behavior will be used against the original index data. If set to true, 'tstats' will only generate results from the TSIDX data that has been automatically generated by the acceleration and non-summarized data will not be provided.&lt;BR /&gt;
Default: false&lt;/P&gt;

&lt;P&gt;in your case searches of the Data model acceleration running without success does your search contains tokens? and what is the acceleration period?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 10:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297646#M947</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-11T10:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297647#M948</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This is the built-in Malware data model with 1 year acceleration period.&lt;BR /&gt;
ACCELERATION&lt;BR /&gt;
Rebuild Update  Edit    &lt;/P&gt;

&lt;P&gt;Status 100.00% Completed &lt;BR /&gt;
Access Count 0. Last Access: -&lt;BR /&gt;&lt;BR /&gt;
Size on Disk  0 B&lt;BR /&gt;&lt;BR /&gt;
Summary Range 31536000 second(s)&lt;BR /&gt;&lt;BR /&gt;
Buckets  96 &lt;BR /&gt;
Updated  1/11/18 11:41:53.000 AM    `&lt;/P&gt;

&lt;P&gt;The search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats prestats=true local=false summariesonly=t allow_old_summaries=true count from datamodel=Malware.Malware_Attacks where * by _time span=10m
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regrads,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 10:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297647#M948</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-01-11T10:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297648#M949</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thanks everyone for the help. Finally looks like the problem have been solved:&lt;BR /&gt;
After I renamed the Add-on to "Enterprise Security conform", the acceleration starts to works... (And ES Endpoint dashboard show the events.) &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/latest/Install/ImportCustomApps"&gt;http://docs.splunk.com/Documentation/ES/latest/Install/ImportCustomApps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I thought it was only due to configuration distribution for Indexer. Looks like I was wrong.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 23:08:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/297648#M949</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-01-20T23:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/660492#M950</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209491"&gt;@ikulcsar&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;have you found a solution to the problem?&lt;BR /&gt;I currently face a similar issue in Splunk 9.0.5 with an accelerated datamodel, completing 100% but with 0 byte size&amp;nbsp;and no results while having 30 buckets and the base-search is returing a million events and no errors.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 09:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/660492#M950</guid>
      <dc:creator>_Tom</dc:creator>
      <dc:date>2023-10-12T09:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Data model acceleration status: Building</title>
      <link>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/661217#M951</link>
      <description>&lt;P&gt;Solution in my case was a field marked as required which was missing in the data - after adding it to the data again the issue was solved.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 15:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Data-model-acceleration-status-Building/m-p/661217#M951</guid>
      <dc:creator>_Tom</dc:creator>
      <dc:date>2023-10-18T15:20:31Z</dc:date>
    </item>
  </channel>
</rss>

