Why has the Data Model Acceleration duplicated the data by 6x?


What could cause DMA to have duplicate data? For example, we have a byte count field in a DMA and when we do a tstats with count and sum the count is 6x the number of events and 6x the sum of the value from the events in the sourcetype.

What search query you are running?

