Splunk Search

Why does tstats command return different results with accelerated vs non-accelerated Data Models?

qs_chuy
Engager

I was working with DataModels and I came across something strange about them when they are accelerated vs when they are not.

 

I created 2 DataModels, TestAccelerated and TestNotAccelerated.

They are a copy of each other with a few differences. The name/id, and one is accelerated and the other is not.

 

When I run a query to get the count of "MyValue" inside of field "MyID", I get different results.

The Accelerated Data Model returns less records, with different grouping of _time than the Non-Accelerated DataModel.

 

I'm curious if anyone knows what the seach difference really is for both accelerated and non accelerated data models.

 

The count ends up being the same, so no issue finding out the count of "MyValue".

 

I see an issue if we are piping the output into a different command that uses the rows for information and not the count in each row, such as `|  geostats`.

 

Query to a non-accelerated data model:

SplunkTestNotAccelerated.png

Query to an accelerated data model:SplunkTestAccelerated.png

 

 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @qs_chuy .. good catch. let me check this and revert back. 

my mindvoice to me... some more "detailed understanding" required between -  the tstats, datamodels, accelerated, non-accelerated, thx

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...