Reporting

Summary range is showing zero after accelerating data model for 7 days in splunk

mayurr98
Super Champion

I have accelerated data model for 7 days.There is a lot of data missing while running queries based on data model

PFA

woodcock
Esteemed Legend

Go to the MC and see if you have skipped searches; you probably do. If so, you have to make sure that you have enough SH horsepower to keep up with your acceleration demands. Also, if you just turned on acceleration, give it a day to get backfilled.

Also, make sure that the results from |from datamodel (which is a non-DM search that uses the constraints of the DM) are the same as the results from |datamodel and |tstats FROM. Also compare to a plain search. This will be revealing.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...