Reporting

Summary range is showing zero after accelerating data model for 7 days in splunk

mayurr98
Super Champion

I have accelerated data model for 7 days.There is a lot of data missing while running queries based on data model

PFA

woodcock
Esteemed Legend

Go to the MC and see if you have skipped searches; you probably do. If so, you have to make sure that you have enough SH horsepower to keep up with your acceleration demands. Also, if you just turned on acceleration, give it a day to get backfilled.

Also, make sure that the results from |from datamodel (which is a non-DM search that uses the constraints of the DM) are the same as the results from |datamodel and |tstats FROM. Also compare to a plain search. This will be revealing.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...