Splunk Search

Why does tstats command return different results with accelerated vs non-accelerated Data Models?

qs_chuy
Engager

I was working with DataModels and I came across something strange about them when they are accelerated vs when they are not.

 

I created 2 DataModels, TestAccelerated and TestNotAccelerated.

They are a copy of each other with a few differences. The name/id, and one is accelerated and the other is not.

 

When I run a query to get the count of "MyValue" inside of field "MyID", I get different results.

The Accelerated Data Model returns less records, with different grouping of _time than the Non-Accelerated DataModel.

 

I'm curious if anyone knows what the seach difference really is for both accelerated and non accelerated data models.

 

The count ends up being the same, so no issue finding out the count of "MyValue".

 

I see an issue if we are piping the output into a different command that uses the rows for information and not the count in each row, such as `|  geostats`.

 

Query to a non-accelerated data model:

SplunkTestNotAccelerated.png

Query to an accelerated data model:SplunkTestAccelerated.png

 

 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @qs_chuy .. good catch. let me check this and revert back. 

my mindvoice to me... some more "detailed understanding" required between -  the tstats, datamodels, accelerated, non-accelerated, thx

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...