Splunk Enterprise

Datamodel populate different result when runs in fast mode vs verbose mode



We recently upgraded to splunk 6.6.3, and recently we noticed strange issue with one of our datamodel

We have datamodel "Datacenter" and below if the query I am running against that datamodel to pull ports and counts. Now when I run below query In fast or smart mode I get different result vs Verbose mode. Something has changed recently after we did upgrade.

Tags (1)
0 Karma

Esteemed Legend

Hi raomu,
I found a similar problem on searches two years ago when searching on many buckets (169) but not present when searching on few buckets (4).
So I opended a case to Splunk Support.
They answered that it was a bug solved in the 6.4.x version, and I verified that the problem isn't still present after upgrade..

0 Karma


What is the query that you are using?

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...