Splunk Search

Why am I getting "Error in 'summarize' command: This search does not support summarization" trying to use KV store lookup with Datamodel Acceleration?

pedromvieira
Communicator

Hi.

I'd like to use KV Store lookup in an accelerated Data Model.
When I set data model this messages occurs:

01-10-2015 12:35:20.817 -0200 ERROR SavedSplunker - savedsearch_id="nobody;MYDM;ACCELERATE_DM_MYDM_MYDM_ACCELERATE", message="Error in 'summarize' command: This search does not support summarization". No actions executed.

My collections.conf

[A]
accelerated_fields.A = {"A": 1,"B": 1,"C": 1}

[B]
accelerated_fields.B = {"B": 1}

My transforms.conf

[A]
collection = A
external_type = kvstore
fields_list = _key,A,B,C

[B]
collection = B
external_type = kvstore
fields_list = _key,B,C,D,E
max_matches = 1
match_type = CIDR(B)
min_matches = 1

groland
Explorer

I have the same issue on my side, unable to accelerate datamodels using KV lookups, error message is This search does not support summarization, evenif I set the replicate setting to true.
When I remove the KV lookup, everything back to normal and the datamodels is accelerated.

Workaround is to setup automatic lookup and in the datamodels, use those new fields like regular fields.

dolezelk
Explorer

that does not populate that field for some reason when using tstat summaryonly

0 Karma

jbjerke_splunk
Splunk Employee
Splunk Employee

Hi

You need to enable replication for the KVstore so it is sent out to the indexers. Datamodel acceleration is performed on the indexers and if the lookup isn't there it won't work.

Your collections.conf

[A]
replicate = true
accelerated_fields.A = {"A": 1,"B": 1,"C": 1}

 [B]
replicate = true
accelerated_fields.B = {"B": 1}

j

BernardEAI
Communicator

This solution worked for me, thanks!

Details on the 

replicate = true

flag is here: https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/Collectionsconf 

0 Karma

ksi_custr
Explorer

Hi,
Is there anyone solved this issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...