Splunk Enterprise Security

Data Model rebuild loose any kind of data from indexers?

N92
Path Finder

If I am rebuilding existing data model in ES then it may be possible to loose any kind of data from indexers?

0 Karma
1 Solution

tiagofbmm
Influencer

Sorry you are correct:

You can search anything on the index no matter what. Any change on DataModels won't ever affect any data in the indexes. The buckets _raw data are not modified when you rebuild a data model. So have no fear doing that, you won't lose any raw data.

What will happen if you rebuild a DM is exactly what it says: you will get a new DM with the new things you set it up with, which will eventually be different from what you had (but I believe this is what you want)

The DataModel are used to standardize different kinds of data that match the same "type". If you have data from different firewall Products, then a DataModel will be very helpful in your searches because they you will be able to search in that DM all the Firewall data from the different vendors in one shot.

But the real big thing about the DataModels are the accelerations. They would make your searches on statistical results maybe a 1000x faster. That is the their major advantage.

If the answer clarifies your question, don't forget to accept

View solution in original post

tiagofbmm
Influencer

Sorry you are correct:

You can search anything on the index no matter what. Any change on DataModels won't ever affect any data in the indexes. The buckets _raw data are not modified when you rebuild a data model. So have no fear doing that, you won't lose any raw data.

What will happen if you rebuild a DM is exactly what it says: you will get a new DM with the new things you set it up with, which will eventually be different from what you had (but I believe this is what you want)

The DataModel are used to standardize different kinds of data that match the same "type". If you have data from different firewall Products, then a DataModel will be very helpful in your searches because they you will be able to search in that DM all the Firewall data from the different vendors in one shot.

But the real big thing about the DataModels are the accelerations. They would make your searches on statistical results maybe a 1000x faster. That is the their major advantage.

If the answer clarifies your question, don't forget to accept

valiquet
Contributor

Yes, can you give us the datamodels.conf stanza for your DMA? Also what is the earliest event in your index that you want to be included in DMA?

./bin/splunk btool list datamodels

or with txt editor

https://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Datamodelsconf

0 Karma

N92
Path Finder

Currently, I have not changed anything. I am just asking if I am adding some events through eval expression & then rebuild data model then is it possible of losing data(logs) from buckets?

Or I can still search data through index?

0 Karma

tiagofbmm
Influencer

The answer is YES, you can search anything on the index no matter what. Any change on DataModels won't ever affect any data in the indexes. The buckets _raw data are not modified when you rebuild a data model. So have no fear doing that, you won't lose any raw data.

What will happen if you rebuild a DM is exactly what it says: you will get a new DM with the new things you set it up with, which will eventually be different from what you had (but I believe this is what you want)

Let me know if you are cleared up.

0 Karma

N92
Path Finder

thanks @tiagofbmm. I got the answer.

0 Karma

N92
Path Finder

Adding one more query. I have huge data of firewall. So if I am create simple data model on ad-hoc search head than if I am running simple search without use of data model than it can run fast due to existing of data model?

0 Karma

tiagofbmm
Influencer

The DataModel are used to standardize different kinds of data that match the same "type". If you have data from different firewall Products, then a DataModel will be very helpful in your searches because they you will be able to search in that DM all the Firewall data from the different vendors in one shot.

But the real big thing about the DataModels are the accelerations. They would make your searches on statistical results maybe a 1000x faster. That is the their major advantage.

If the answer clarifies your question, don't forget to accept

0 Karma

N92
Path Finder

Again Thanks @tiagofbmm , I am not able to accept your answer. Maybe because it's comment section. Can you write something in answer section so maybe I got the option of acceptance?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...