Reporting

Summary range is showing zero after accelerating data model for 7 days in splunk

mayurr98
Super Champion

I have accelerated data model for 7 days.There is a lot of data missing while running queries based on data model

PFA

woodcock
Esteemed Legend

Go to the MC and see if you have skipped searches; you probably do. If so, you have to make sure that you have enough SH horsepower to keep up with your acceleration demands. Also, if you just turned on acceleration, give it a day to get backfilled.

Also, make sure that the results from |from datamodel (which is a non-DM search that uses the constraints of the DM) are the same as the results from |datamodel and |tstats FROM. Also compare to a plain search. This will be revealing.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...