<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Model Acceleration with multiple root events in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125743#M2839</link>
    <description>&lt;P&gt;OK, this is weird - not the first bad case regarding datamodels .... open a ticket @ splunk!&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jul 2014 15:26:55 GMT</pubDate>
    <dc:creator>Rocket66</dc:creator>
    <dc:date>2014-07-01T15:26:55Z</dc:date>
    <item>
      <title>Data Model Acceleration with multiple root events</title>
      <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125740#M2836</link>
      <description>&lt;P&gt;So after some fiddling with Data Models in Splunk 6.1.1, I created a really simple one which uses the internal indexes. It is based on two root events to start: Internal (constraint: index=_internal) and Audit (constraint: index=_audit). Internal has some child objects:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/dm1.gif" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;The model is being accelerated with a timeframe of 1 month. But when opening Pivot and selecting the first root event (Internal) the model returns 0&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/dm2.gif" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;While the second root event (Audit) still works fine.&lt;/P&gt;

&lt;P&gt;When taking a look at debug logging for the DataModel component, somehow the second root object is accelerated (which conflicts with the documentation stating &lt;STRONG&gt;only&lt;/STRONG&gt; the first root event object is accelerated). On top of this the first root event object doesn't do anything anymore.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/dm3.gif" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Once acceleration on the model is turned off both root event objects work perfectly. Removing the second root event object and then accelerating the model also keeps the model working.&lt;/P&gt;

&lt;P&gt;Why is Splunk trying to accelerate the second root event instead of the first? And why does this completely break the first root object, isn't Pivot supposed to fill up the missing frames with raw data?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:58:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125740#M2836</guid>
      <dc:creator>qjvtenkroode</dc:creator>
      <dc:date>2020-09-28T16:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model Acceleration with multiple root events</title>
      <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125741#M2837</link>
      <description>&lt;P&gt;Maybe the order is done alphabetic ascending, and not chronological/hierarchical?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 13:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125741#M2837</guid>
      <dc:creator>Rocket66</dc:creator>
      <dc:date>2014-07-01T13:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model Acceleration with multiple root events</title>
      <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125742#M2838</link>
      <description>&lt;P&gt;Sadly enough this is not the case, when I use another name for the root event (in this case I tried this with the name "Whatever", which should be one of the last ones if done alphabetically)  the same thing occurs.&lt;/P&gt;

&lt;P&gt;The worst part is this even happens in the SAMPLE data models which are there by default. Adding a second root event and accelerating makes the second root event the accelerated one, breaks the first root event while any other root events (e.g. the third, fourth and so on) still work but won't benefit data model acceleration except for ad-hoc acceleration.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 15:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125742#M2838</guid>
      <dc:creator>qjvtenkroode</dc:creator>
      <dc:date>2014-07-01T15:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model Acceleration with multiple root events</title>
      <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125743#M2839</link>
      <description>&lt;P&gt;OK, this is weird - not the first bad case regarding datamodels .... open a ticket @ splunk!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 15:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125743#M2839</guid>
      <dc:creator>Rocket66</dc:creator>
      <dc:date>2014-07-01T15:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model Acceleration with multiple root events</title>
      <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125744#M2840</link>
      <description>&lt;P&gt;Don't create multiple Root Events in a model so you don't give a chance to Splunk to mess up &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 10:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125744#M2840</guid>
      <dc:creator>sibbsnb</dc:creator>
      <dc:date>2015-03-20T10:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Data Model Acceleration with multiple root events</title>
      <link>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125745#M2841</link>
      <description>&lt;P&gt;Acceleration has restrictions,  check this out....&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/Knowledge/Aboutdatamodels"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/Knowledge/Aboutdatamodels&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To accelerate a data model, it must contain at least one root event dataset, or one root search dataset that only uses streaming commands. Acceleration only affects these dataset types and datasets that are children of those root datasets. &lt;STRONG&gt;You cannot accelerate root search datasets that use nonstreaming commands (including transforming commands), root transaction datasets, and children of those datasets. Data models can contain a mixture of accelerated and unaccelerated datasets.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 22:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Data-Model-Acceleration-with-multiple-root-events/m-p/125745#M2841</guid>
      <dc:creator>lrod99</dc:creator>
      <dc:date>2018-03-27T22:07:27Z</dc:date>
    </item>
  </channel>
</rss>

