Why has the Data Model Acceleration duplicated the data by 6x?


What could cause DMA to have duplicate data? For example, we have a byte count field in a DMA and when we do a tstats with count and sum the count is 6x the number of events and 6x the sum of the value from the events in the sourcetype.

0 Karma


What search query you are running?

0 Karma