Splunk Enterprise
Highlighted

Search in datamodel

Path Finder

Hi Splunk team

The image below is information about my datamodel.
Summary Range 31622400 second (s)
But why do I search for a period of May, the result returns 0 events?

vumanhtai_0-1593500678155.png

How can i fix it?

Thank all!

Tags (1)
0 Karma
Highlighted

Re: Search in datamodel

Contributor

@vumanhtai 

Couple of Q's

whats your SPL command to search the datamodel?

Are you using summariesonly=t in the tstats?

Does the source index has the data for mentioned time period?

The datamodel Status is 92.33% means its not yet completed building the summaries. If you are using summariesonly=t, try removing that attribute and see if it returns all the data.

 

 

Highlighted

Re: Search in datamodel

Path Finder

Hi anilchaithu

my search : | tstats count from datamodel=pan_firewall

 source index has the data for mentioned time period.

i don't use summariesonly=t in search 

Thanks!

Tags (1)
0 Karma