Splunk Search

Why does tstats command return different results with accelerated vs non-accelerated Data Models?

qs_chuy
Engager

I was working with DataModels and I came across something strange about them when they are accelerated vs when they are not.

 

I created 2 DataModels, TestAccelerated and TestNotAccelerated.

They are a copy of each other with a few differences. The name/id, and one is accelerated and the other is not.

 

When I run a query to get the count of "MyValue" inside of field "MyID", I get different results.

The Accelerated Data Model returns less records, with different grouping of _time than the Non-Accelerated DataModel.

 

I'm curious if anyone knows what the seach difference really is for both accelerated and non accelerated data models.

 

The count ends up being the same, so no issue finding out the count of "MyValue".

 

I see an issue if we are piping the output into a different command that uses the rows for information and not the count in each row, such as `|  geostats`.

 

Query to a non-accelerated data model:

SplunkTestNotAccelerated.png

Query to an accelerated data model:SplunkTestAccelerated.png

 

 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @qs_chuy .. good catch. let me check this and revert back. 

my mindvoice to me... some more "detailed understanding" required between -  the tstats, datamodels, accelerated, non-accelerated, thx

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...