Splunk Dev

Data model not accelerating data older than a year

sarit_s
Communicator

Hello
i have data model acceleration configured for all time.

i have data indexed for 16 months but when im running my query with 

 

summariesonly=true

 

 im getting less results than when im running 

 

summariesonly=false

 

and the latest data is a year ago

also, i see this error msg in the data model page :

 

Error in data model "events_prod" : JSON file contents not available.

 

 i don't know if it is related or not ...

i couldn't find any errors in the logs

i've added to datamodels.conf this stanza:

 

acceleration.allow_skew = 100%

 

but it didn't help.

any suggestion ?

thanks

sarit 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...