Dashboards & Visualizations

Percent complete for data models

awmorris
Path Finder

If a an accelerated data model is 80% complete, what does that ACTUALLY mean? Does it mean I have 80% of the events? 80% of the time? 80% of the data?

Almost half my data models are not keeping up at even close to 100% but i can't figure out what is actually "missing" from the data models.

Tags (1)
0 Karma

awmorris
Path Finder

I'll refine my question to try to drive out the answer I need... can someone give me a SPL formula I can use to self calculate the percent complete. If I can get the formula, that will tell me the information I am trying to discover. My problem is my data model is at 55% complete and heading south every day.

0 Karma

gjanders
SplunkTrust
SplunkTrust

I have a couple of dashboards in Alerts for Splunk Admins for this purpose, git links here and here

Do they help? As you can see they are based on a conf presentation that is worth watching!

0 Karma

tom_frotscher
Builder

Hi,

i do not know the exact definition of this field. But for my experience, it says that in your case 80% of your configured summary range is accelerated (for example 32 out of 40 days).

If this value is not progressing, you might have to many running searches. The data model acceleration is driven by scheduled searches in the background. Can you check the management console for skipped scheduled searches?

Greetings,

Tom

0 Karma

awmorris
Path Finder

Thanks but that's not it. I have events for each of the 30 days in the data model.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...