Splunk Search

Why does tstats command return different results with accelerated vs non-accelerated Data Models?

qs_chuy
Engager

I was working with DataModels and I came across something strange about them when they are accelerated vs when they are not.

 

I created 2 DataModels, TestAccelerated and TestNotAccelerated.

They are a copy of each other with a few differences. The name/id, and one is accelerated and the other is not.

 

When I run a query to get the count of "MyValue" inside of field "MyID", I get different results.

The Accelerated Data Model returns less records, with different grouping of _time than the Non-Accelerated DataModel.

 

I'm curious if anyone knows what the seach difference really is for both accelerated and non accelerated data models.

 

The count ends up being the same, so no issue finding out the count of "MyValue".

 

I see an issue if we are piping the output into a different command that uses the rows for information and not the count in each row, such as `|  geostats`.

 

Query to a non-accelerated data model:

SplunkTestNotAccelerated.png

Query to an accelerated data model:SplunkTestAccelerated.png

 

 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @qs_chuy .. good catch. let me check this and revert back. 

my mindvoice to me... some more "detailed understanding" required between -  the tstats, datamodels, accelerated, non-accelerated, thx

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...