Splunk Search

Datamodel tstats search and normal search result is not same

burakatabay
Path Finder

Hi,

I run two splunk search and results not come same.

In the first search is with tstats ;

timeprefix = yesterday

| tstats `summariesonly` count from datamodel=Authentication.Authentication where index=wineventlog Authentication.user=some_user

result is = 8990

In the second search ;

index=wineventlog  user=some_user tag=authentication NOT (action=success user=*$)| stats count

result is = 9000

 

Why datamodel and normal splunk search result is different ? 

Also ;

Datamodel accelaration status is %99 ? 

Could the problem be caused by this?

 

Thank you.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The summariesonly option tells tstats to look only at events that are in the accelerated datamodel.  If the DMA is not complete then the results also will not be complete.

---
If this reply helps you, Karma would be appreciated.
0 Karma

burakatabay
Path Finder

My DMA is never been %100. it's generally %99.x . Why is this happening ? 

How ı find the problem ? 

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...