<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What do we mean by multiple root event search in Data Model Acceleration? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305126#M2666</link>
    <description>&lt;P&gt;even easier. Just upgrade to the latest version that you want then.  I see no problem with 6.6.3 either.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2017 07:17:20 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2017-08-31T07:17:20Z</dc:date>
    <item>
      <title>What do we mean by multiple root event search in Data Model Acceleration?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305123#M2663</link>
      <description>&lt;P&gt;Hello to all the Splunkers!&lt;/P&gt;

&lt;P&gt;I have an very important question which needs to be addressed before we do an uplift of our Splunk version.&lt;/P&gt;

&lt;P&gt;We are planning to uplift our Splunk version from 6.3.2 to &lt;STRONG&gt;6.6.2 or 6.6.3&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;We are using data model acceleration in our current Splunk version i.e. &lt;STRONG&gt;6.3.2&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;As Splunk &lt;STRONG&gt;6.6.3&lt;/STRONG&gt; is very new release (21 August 17) so mind says we should go with &lt;STRONG&gt;6.6.2&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Her comes the bone of contention I see following in 6.6.3 release notes:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Date resolved                      Issue number                   Description&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;2017-07-25                          SPL-142801, SPL-142771    Only one root event search in a DM gets accelerated&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I have no idea what is meant by this above Issue and this is making me wonder which Splunk version I should go for.&lt;/P&gt;

&lt;P&gt;As far as my limited knowledge with Splunk I knew that we can have only one root event per data model and that is the way our current Data Model are designed.&lt;/P&gt;

&lt;P&gt;Please help me clear my understanding and let us decide which Splunk version shall we go for.&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Inderjot Singh Rasila&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 23:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305123#M2663</guid>
      <dc:creator>inderjot_rasila</dc:creator>
      <dc:date>2017-08-29T23:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: What do we mean by multiple root event search in Data Model Acceleration?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305124#M2664</link>
      <description>&lt;P&gt;If this is the case then you have nothing to worry about as it relates to your datamodels:&lt;/P&gt;

&lt;P&gt;"As far as my limited knowledge with Splunk I knew that we can have only one root event per data model and that is the way our current Data Model are designed."&lt;/P&gt;

&lt;P&gt;Just make sure you follow the clustered indexer upgrade instructions if you're in a clustered environment:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Upgradeacluster"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Upgradeacluster&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 01:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305124#M2664</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-08-30T01:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: What do we mean by multiple root event search in Data Model Acceleration?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305125#M2665</link>
      <description>&lt;P&gt;Thanks @jkat. Currently we do not have index clustering enabled &lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 04:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305125#M2665</guid>
      <dc:creator>inderjot_rasila</dc:creator>
      <dc:date>2017-08-31T04:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: What do we mean by multiple root event search in Data Model Acceleration?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305126#M2666</link>
      <description>&lt;P&gt;even easier. Just upgrade to the latest version that you want then.  I see no problem with 6.6.3 either.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 07:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-do-we-mean-by-multiple-root-event-search-in-Data-Model/m-p/305126#M2666</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-08-31T07:17:20Z</dc:date>
    </item>
  </channel>
</rss>

