Splunk Enterprise

Search in datamodel

vumanhtai
Path Finder

Hi Splunk team

The image below is information about my datamodel.
Summary Range 31622400 second (s)
But why do I search for a period of May, the result returns 0 events?

vumanhtai_0-1593500678155.png

How can i fix it?

Thank all!

Labels (2)
Tags (1)
0 Karma

anilchaithu
Builder

@vumanhtai 

Couple of Q's

whats your SPL command to search the datamodel?

Are you using summariesonly=t in the tstats?

Does the source index has the data for mentioned time period?

The datamodel Status is 92.33% means its not yet completed building the summaries. If you are using summariesonly=t, try removing that attribute and see if it returns all the data.

 

 

vumanhtai
Path Finder

Hi anilchaithu

my search : | tstats count from datamodel=pan_firewall

 source index has the data for mentioned time period.

i don't use summariesonly=t in search 

Thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...