Splunk Enterprise

Datamodel populate different result when runs in fast mode vs verbose mode

raomu
Explorer

HI,

We recently upgraded to splunk 6.6.3, and recently we noticed strange issue with one of our datamodel

We have datamodel "Datacenter" and below if the query I am running against that datamodel to pull ports and counts. Now when I run below query In fast or smart mode I get different result vs Verbose mode. Something has changed recently after we did upgrade.

Tags (1)
0 Karma

gcusello
Legend

Hi raomu,
I found a similar problem on searches two years ago when searching on many buckets (169) but not present when searching on few buckets (4).
So I opended a case to Splunk Support.
They answered that it was a bug solved in the 6.4.x version, and I verified that the problem isn't still present after upgrade..
Bye.
Giuseppe

0 Karma

deepashri_123
Motivator

What is the query that you are using?

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!