Reporting

Why isn't my datamodel doesnt returning any data?

graju89
Path Finder

Hi all,

I have upgraded my Splunk from 6.6.6 to 7.1.1 and installed a new Splunk CIM version(4.12). I accelerated a few data models like malware, network traffic and change analysis. Malware data model is 100% completed. When I try with the search query | tstats count from datamodel=Malware | sort -count, it returns 28. So i assume the data model has some data. But it is not showing any data from it.

Note: other data models are in the process of building. My search peers are running 6.6.6(I dont think it matters)

Any idea why it is not showing any data?

0 Karma

graju89
Path Finder

Just an update for the above post. setting summariesonly=f returns data. Also, the statistics of accelerated data is:
Status 100.00% Completed
Access Count 950. Last Access: 11/1/18 11:23:04.000 AM
Size on Disk 167.26 GB
Summary Range 7948800 second(s)
Buckets 1787
Updated 11/1/18 10:54:35.000 AM

Everything looks good. Dont know why summariesonly=true doesnt return anything

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...