Reporting

Splunk App for Web Analytics data model acceleration is not completing

vikas_gopal
Builder

HI Experts,

I am sure someone must have faced this issue with

Web Analytics 2.2.1
Splunk 7.2.5 (SHC, Index Cluster

as I have seen similar posts but no concrete Answer . I am aware that when we install this app we will get Web data model.Because i already have CIM so I have cloned this data model and named it "Web Analytics" . I can see the data as it is properly tagged (tag=web), this gives me the results as expected. I have accelerated this data model for summary range 1 day. Till 99.98% it completed in 30 min but then it stuck for like 48 hours now , as shown below . I tried rebuilding it still same status

MODEL
Datasets
3 Events, 1 Search Event Edit
Permissions
Shared Globally. Owned by nobody.   Edit
ACCELERATION
Rebuild Update  Edit
Status
99.98% Completed
Access Count
0. Last Access: -
Size on Disk
1.91 GB
Summary Range
86400 second(s)
Buckets
1006
Updated
5/10/20 7:04:00.000 PM"

I do not know if because of this dashboards like (Analytics Center,Audience,Acquisition,Behavior Overview) are blank . Couple of other observations
Below query does not produce any results as Web.eventtype=pageview produce no results

| tstats summariesonly=t prestats=t dc(Web.http_session) FROM datamodel=`datamodel` WHERE Web.site="*" Web.eventtype=pageview GROUPBY Web.http_session,Web.ua_mobile
_time span=1d  | timechart span=1d dc(Web.http_session) by Web.ua_mobile  | rename Web.ua_mobile AS "Mobile Device "  | fields - VALUE

I have also checked Document link in the app itself and can see below

Web Server Log Data check (tag=web | head 5)  check completed
Website Configuration check --table is showing results  
Lookup check --(Sessions,Pages) ---check completed
Data Model Acceleration check --98.99%

Any help will be highly appreciated.

| tstats summariesonly=t prestats=t count FROM datamodel=WebAnalytics --> Produce no Result
| tstats count FROM datamodel=WebAnalytics --> Produced results

VG

Labels (2)
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...