Splunk Enterprise
Highlighted

Search in datamodel

Path Finder

Hi Splunk team

The image below is information about my datamodel.
Summary Range 31622400 second (s)
But why do I search for a period of May, the result returns 0 events?

vumanhtai_0-1593500678155.png

How can i fix it?

Thank all!

Tags (1)
0 Karma
Highlighted

Re: Search in datamodel

Communicator

@vumanhtai 

Couple of Q's

whats your SPL command to search the datamodel?

Are you using summariesonly=t in the tstats?

Does the source index has the data for mentioned time period?

The datamodel Status is 92.33% means its not yet completed building the summaries. If you are using summariesonly=t, try removing that attribute and see if it returns all the data.

 

 

Highlighted

Re: Search in datamodel

Path Finder

Hi anilchaithu

my search : | tstats count from datamodel=pan_firewall

 source index has the data for mentioned time period.

i don't use summariesonly=t in search 

Thanks!

Tags (1)
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.