Splunk Search

How come my data model is accelerating within 5 secs but can't fetch the data from data model?

parthiv
Explorer

When we start the acceleration of a data model, it completes successfully. But, when we run the below query, we are not able to fetch the data.

| tstats summariesonly=t count from datamodel="datamodel_name"

It gives the 0 counts.

But, when we run the following query we are able to fetch the data.

| tstats summariesonly=false count from datamodel="datamodel_name"

it gives the 1034 count.

So please let me know if I am doing something wrong.

NOTE:
We have checked the acceleration period and it has the data.
Splunk version : 6.5.3
And I am facing this issue on a specific Splunk instance only.

deepashri_123
Motivator

Hey@parthiv,

Is your datamodel accelerated? What is the size of the datamodel ? Is the datamodel accelerated for the time-period that you are running?

0 Karma

parthiv
Explorer

Hey,

Yes my datamodel is accelerated.
Size of datamodel is 0.06 constant.

Yes we ran for the same time.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...