Splunk Enterprise

Datamodel populate different result when runs in fast mode vs verbose mode



We recently upgraded to splunk 6.6.3, and recently we noticed strange issue with one of our datamodel

We have datamodel "Datacenter" and below if the query I am running against that datamodel to pull ports and counts. Now when I run below query In fast or smart mode I get different result vs Verbose mode. Something has changed recently after we did upgrade.

Tags (1)
0 Karma

Esteemed Legend

Hi raomu,
I found a similar problem on searches two years ago when searching on many buckets (169) but not present when searching on few buckets (4).
So I opended a case to Splunk Support.
They answered that it was a bug solved in the 6.4.x version, and I verified that the problem isn't still present after upgrade..

0 Karma


What is the query that you are using?

0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...