Splunk Enterprise

Search in datamodel

vumanhtai
Path Finder

Hi Splunk team

The image below is information about my datamodel.
Summary Range 31622400 second (s)
But why do I search for a period of May, the result returns 0 events?

vumanhtai_0-1593500678155.png

How can i fix it?

Thank all!

Labels (2)
Tags (1)
0 Karma

anilchaithu
Builder

@vumanhtai 

Couple of Q's

whats your SPL command to search the datamodel?

Are you using summariesonly=t in the tstats?

Does the source index has the data for mentioned time period?

The datamodel Status is 92.33% means its not yet completed building the summaries. If you are using summariesonly=t, try removing that attribute and see if it returns all the data.

 

 

vumanhtai
Path Finder

Hi anilchaithu

my search : | tstats count from datamodel=pan_firewall

 source index has the data for mentioned time period.

i don't use summariesonly=t in search 

Thanks!

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...