Splunk Enterprise

Search in datamodel

vumanhtai
Path Finder

Hi Splunk team

The image below is information about my datamodel.
Summary Range 31622400 second (s)
But why do I search for a period of May, the result returns 0 events?

vumanhtai_0-1593500678155.png

How can i fix it?

Thank all!

Labels (2)
Tags (1)
0 Karma

anilchaithu
Builder

@vumanhtai 

Couple of Q's

whats your SPL command to search the datamodel?

Are you using summariesonly=t in the tstats?

Does the source index has the data for mentioned time period?

The datamodel Status is 92.33% means its not yet completed building the summaries. If you are using summariesonly=t, try removing that attribute and see if it returns all the data.

 

 

vumanhtai
Path Finder

Hi anilchaithu

my search : | tstats count from datamodel=pan_firewall

 source index has the data for mentioned time period.

i don't use summariesonly=t in search 

Thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...