Splunk Search

How come my data model is accelerating within 5 secs but can't fetch the data from data model?

parthiv
Explorer

When we start the acceleration of a data model, it completes successfully. But, when we run the below query, we are not able to fetch the data.

| tstats summariesonly=t count from datamodel="datamodel_name"

It gives the 0 counts.

But, when we run the following query we are able to fetch the data.

| tstats summariesonly=false count from datamodel="datamodel_name"

it gives the 1034 count.

So please let me know if I am doing something wrong.

NOTE:
We have checked the acceleration period and it has the data.
Splunk version : 6.5.3
And I am facing this issue on a specific Splunk instance only.

deepashri_123
Motivator

Hey@parthiv,

Is your datamodel accelerated? What is the size of the datamodel ? Is the datamodel accelerated for the time-period that you are running?

0 Karma

parthiv
Explorer

Hey,

Yes my datamodel is accelerated.
Size of datamodel is 0.06 constant.

Yes we ran for the same time.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...