Hello,
I recently tuned my Authentication Datamodel and I cannot see any result in the action field while running a search.
However I can see the result while using Pivot feature.
FYI - I used Eval Expression feature while tuning this DM.
case((sourcetype="linux" AND isnull(action)),"unknown",sourcetype="linux", action,
sourcetype="AWS",action,
(sourcetype="Okta" AND action="SUCCESS"), "success",
(sourcetype="Okta" AND action="FAILURE"), "failure",
(sourcetype="Duo" AND action="SUCCESS"), "success",
(sourcetype="Duo" AND action="FAILURE"), "failure" )
After you "tuned" the DM did you re-enable acceleration and allow time for the acceleration to complete?
Hello @richgalloway,
Yeah, I enabled acceleration and it has been a week since i accelerated it. I can run searches on the datamodel using tsats command but it's only problem is that it won't populate action field in the result. You can see that in the first screenshot I shared.
Next steps are:
1) Verify the acceleration is 100% complete.
2) Run the tstats query using the summariesonly=false option. If you get the expected results then there's a problem with the DM acceleration.
1) Datamodel acceleration is 100%.
2) With summariesonly=false option I got the same result. Action field did not populate.