Reporting

Summary range is showing zero after accelerating data model for 7 days in splunk

mayurr98
Super Champion

I have accelerated data model for 7 days.There is a lot of data missing while running queries based on data model

PFA

woodcock
Esteemed Legend

Go to the MC and see if you have skipped searches; you probably do. If so, you have to make sure that you have enough SH horsepower to keep up with your acceleration demands. Also, if you just turned on acceleration, give it a day to get backfilled.

Also, make sure that the results from |from datamodel (which is a non-DM search that uses the constraints of the DM) are the same as the results from |datamodel and |tstats FROM. Also compare to a plain search. This will be revealing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...