Splunk Search

How come my data model is accelerating within 5 secs but can't fetch the data from data model?


When we start the acceleration of a data model, it completes successfully. But, when we run the below query, we are not able to fetch the data.

| tstats summariesonly=t count from datamodel="datamodel_name"

It gives the 0 counts.

But, when we run the following query we are able to fetch the data.

| tstats summariesonly=false count from datamodel="datamodel_name"

it gives the 1034 count.

So please let me know if I am doing something wrong.

We have checked the acceleration period and it has the data.
Splunk version : 6.5.3
And I am facing this issue on a specific Splunk instance only.



Is your datamodel accelerated? What is the size of the datamodel ? Is the datamodel accelerated for the time-period that you are running?

0 Karma



Yes my datamodel is accelerated.
Size of datamodel is 0.06 constant.

Yes we ran for the same time.

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!