<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Accelerated data model with higher event count than corresponding indexed data in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Accelerated-data-model-with-higher-event-count-than/m-p/405630#M6776</link>
    <description>&lt;P&gt;Has anyone seen an issue where an accelerated data model has duplicate events in tsidx files? Occasionally I encounter an issue where there are many more records in the accelerated data model compared to the corresponding index data. &lt;/P&gt;

&lt;P&gt;I get the data model event count using &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count from datamodel=&amp;lt;datamodel&amp;gt; by _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And also see the high count in the pivot GUI. Rebuilding the data model will correct it so that the event counts match. I'd like to be able to prevent this from happening or at least understand why it occurs. &lt;BR /&gt;
Around the time that the data model gets 'corrupted', I've noticed a lot of &lt;CODE&gt;sourcetype=splunkd_access&lt;/CODE&gt; events are generated with a URI that looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/servicesNS/user1/myapp/admin/summarization/tstats%3ADM_myapp_mydatamodel/touch
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The  &lt;CODE&gt;user1&lt;/CODE&gt; in this URI has limited permissions.  They have access to &lt;CODE&gt;accelerate_search&lt;/CODE&gt; but not to &lt;CODE&gt;schedule_search&lt;/CODE&gt; which I think is is required for &lt;CODE&gt;accelerate_search&lt;/CODE&gt; to be truly enabled. Anyway this URI is as close as I've been able to get to any sort of explanation. I never see it except when this issue is occurring.  Is there any way to block a user role from executing this 'touch' search? Is this a cause or just another symptom?&lt;/P&gt;

&lt;P&gt;There are 12 datamodels in my app and this is happening to all of them except the slimmest 1 or 2. It occurs most often when the system has a lot of incoming data to crunch so it does seem to be process- or resource-related.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Feb 2019 14:51:33 GMT</pubDate>
    <dc:creator>camillak</dc:creator>
    <dc:date>2019-02-22T14:51:33Z</dc:date>
    <item>
      <title>Accelerated data model with higher event count than corresponding indexed data</title>
      <link>https://community.splunk.com/t5/Reporting/Accelerated-data-model-with-higher-event-count-than/m-p/405630#M6776</link>
      <description>&lt;P&gt;Has anyone seen an issue where an accelerated data model has duplicate events in tsidx files? Occasionally I encounter an issue where there are many more records in the accelerated data model compared to the corresponding index data. &lt;/P&gt;

&lt;P&gt;I get the data model event count using &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count from datamodel=&amp;lt;datamodel&amp;gt; by _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And also see the high count in the pivot GUI. Rebuilding the data model will correct it so that the event counts match. I'd like to be able to prevent this from happening or at least understand why it occurs. &lt;BR /&gt;
Around the time that the data model gets 'corrupted', I've noticed a lot of &lt;CODE&gt;sourcetype=splunkd_access&lt;/CODE&gt; events are generated with a URI that looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/servicesNS/user1/myapp/admin/summarization/tstats%3ADM_myapp_mydatamodel/touch
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The  &lt;CODE&gt;user1&lt;/CODE&gt; in this URI has limited permissions.  They have access to &lt;CODE&gt;accelerate_search&lt;/CODE&gt; but not to &lt;CODE&gt;schedule_search&lt;/CODE&gt; which I think is is required for &lt;CODE&gt;accelerate_search&lt;/CODE&gt; to be truly enabled. Anyway this URI is as close as I've been able to get to any sort of explanation. I never see it except when this issue is occurring.  Is there any way to block a user role from executing this 'touch' search? Is this a cause or just another symptom?&lt;/P&gt;

&lt;P&gt;There are 12 datamodels in my app and this is happening to all of them except the slimmest 1 or 2. It occurs most often when the system has a lot of incoming data to crunch so it does seem to be process- or resource-related.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 14:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Accelerated-data-model-with-higher-event-count-than/m-p/405630#M6776</guid>
      <dc:creator>camillak</dc:creator>
      <dc:date>2019-02-22T14:51:33Z</dc:date>
    </item>
  </channel>
</rss>

