Splunk Enterprise Security

Data Models not being accelerated for Enterprise Security in Splunk 6.0.2

lehrfeld
Path Finder

Hi All -
We have an interesting issue that we just discovered. While attempting to get ES dashboards populated we stumbled across the "Data Model Audit" dashboard in ES. It appears from the Acceleration Details pane that none of our DMs are being accelerated properly. They are in various stages of completeness...

For example, our Network_Traffic DM has an earliest of 12/31/1969 20:00:00 and a latest of 05/11/2032 01:17:20. with 1.5% being completed.

Network_Traffic  Splunk_SA_CIM  1-56/5 * * * *  91  12/31/1969 20:00:00  05/11/2032 01:17:20  1  1.5  0.0

I tried to rebuild it last night and the is says 'completed' but I think it is trying to fool me.

Any ideas on how to trouble shoot this type of issue?

Thanks!

Mike

hardikJsheth
Motivator

What amount of data do you have in your SPLUNK?

You can improve performance of data models by performing following tasks:
1) By default all CIM models look through all indexes. If you know that data is coming from specific index, add it in the base search of the data model.

2) There are two tunable nobes, acceleration.earliest_time and acceleration.backfill_time.

Attaching one PPT, which has some explanation on how to optimize Data Model. link text

0 Karma

cesaccenturefed
Path Finder

We also have a similar issue, we have to do a rolling restart very often on our ES search head cluster, Then Data models need to be rebuilt, I don't think that such maintenance would be needed for our es data models. are there any best practices or solutions to keep data models in line?

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...