Hi all,
I have upgraded my Splunk from 6.6.6 to 7.1.1 and installed a new Splunk CIM version(4.12). I accelerated a few data models like malware, network traffic and change analysis. Malware data model is 100% completed. When I try with the search query | tstats count from datamodel=Malware | sort -count
, it returns 28. So i assume the data model has some data. But it is not showing any data from it.
Note: other data models are in the process of building. My search peers are running 6.6.6(I dont think it matters)
Any idea why it is not showing any data?
Just an update for the above post. setting summariesonly=f returns data. Also, the statistics of accelerated data is:
Status 100.00% Completed
Access Count 950. Last Access: 11/1/18 11:23:04.000 AM
Size on Disk 167.26 GB
Summary Range 7948800 second(s)
Buckets 1787
Updated 11/1/18 10:54:35.000 AM
Everything looks good. Dont know why summariesonly=true doesnt return anything