<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk CIM Data Model Acceleration in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574187#M8679</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231311"&gt;@IoannisG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the use of the reference hardware is useful even if your system is underused because it's the first notation when you open a Case to Splunk Support.&lt;/P&gt;&lt;P&gt;let me know if you solved.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 09 Nov 2021 12:09:24 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-11-09T12:09:24Z</dc:date>
    <item>
      <title>Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574154#M8674</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am working on a Distributed environment with:&lt;/P&gt;&lt;P&gt;- 1x SH with Splunk ES installed (Deployment Server)&lt;BR /&gt;- 7x Indexers (Search Peers)&lt;/P&gt;&lt;P&gt;On my SH, I see a lot of skipped executions on scheduled searches related to Splunk CIM app.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Specifically I see a 99% skip ratio to scheduled reports with a name format of:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;_ACCELERATE_DM_Splunk_SA_CIM_Splunk_CIM_Validation.[Datamode_Name]_ACCELERATE_&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I accessed the Data Models page and expanded the CIM Validation (S.o.S) data model. The information I got is:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Access Count: 0 - Last Access: -) while size is 750MB and frequently updated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My question:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can I disable acceleration on this Data Model since it is never accessed?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With kind regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Chris&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 09:59:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574154#M8674</guid>
      <dc:creator>IoannisG</dc:creator>
      <dc:date>2021-11-09T09:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574161#M8675</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231311"&gt;@IoannisG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first, the ES Search Head must be a dedicated server and you cannot use it also as Deployment Server, in addition, if your Deployment Server has more than 50 clients, it requires a dedicated server.&lt;/P&gt;&lt;P&gt;Then, what are the resources of your SH and Indexers?&lt;/P&gt;&lt;P&gt;Remember that the minimum reference hardware is:&lt;/P&gt;&lt;P&gt;for an ES Search Head:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;16 Physical CPUs or 32 virtual CPUs&lt;/LI&gt;&lt;LI&gt;32 GB RAM&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;for Mid Tier Indexers:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;24 physical CPUs or 48 virtual CPUs&lt;/LI&gt;&lt;LI&gt;64 GB RAM&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Anyway, you can disable the above acceleration but the warning you are receiving is only an alert of a situation, in other words, if you haven't sufficient resources, if you disable this acceleration, probably you'll have a similar message for another acceleration.&lt;/P&gt;&lt;P&gt;So start to check your resources, then, using the Monitor Console, see if there is some heavy scheduled search that gives problem to your system.&lt;/P&gt;&lt;P&gt;At least, if the resources are correct and there isn't any heavy scheduled search, open a Case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 10:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574161#M8675</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-09T10:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574169#M8676</link>
      <description>&lt;P&gt;Ciao Guiseppe,&lt;/P&gt;&lt;P&gt;my resources (CPU) are less on Search Peers than the recommended ones but I am aware about it already. Specifically:&lt;/P&gt;&lt;P&gt;Search Head: 32 vCPUs - 128GB RAM&lt;BR /&gt;Search Peers: &lt;STRONG&gt;6vCPUs - 40GB RAM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have less than 10 clients/indexers in total.&lt;/P&gt;&lt;P&gt;Transparent Huge Pages and ulimits are optimized on all instances and health checks are green (except skipped searches).&lt;/P&gt;&lt;P&gt;Things I have manually changed/configured so far that might affect:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Search Head &amp;amp; Search Peers - limits.conf&lt;/STRONG&gt;&lt;BR /&gt;base_max_searches = 10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;On both Search Head and Search Peers:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Relative concurrency limit for scheduled searches: 60&lt;BR /&gt;&lt;/SPAN&gt;Relative concurrency limit for summarization searches: 100&lt;BR /&gt;&lt;BR /&gt;I have disabled acceleration for Splunk CIM and for around an hour now the aggregate search runtime has dramatically fallen (before the datamodel acceleration searches from Splunk CIM were delaying the runtime). I still see the red exclamation warning though but I assume it is using historical data so maybe I shall wait a bit, right?&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 11:19:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574169#M8676</guid>
      <dc:creator>IoannisG</dc:creator>
      <dc:date>2021-11-09T11:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574178#M8677</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231311"&gt;@IoannisG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;probably the problem is the number of CPUs in your Indexers: remember that each search (and each subsearch) takes a CPU and release it only when finished.&lt;/P&gt;&lt;P&gt;Then how many logs you index every day?&lt;/P&gt;&lt;P&gt;Using ES you should have at max an indexer for every 80-100 GB/day, so if you dayly index 1TB of logs, you need at least 10 Indexers with the reference hardware I described.&lt;/P&gt;&lt;P&gt;Could you have more CPUs?&lt;/P&gt;&lt;P&gt;You should also have errors from ES and Health Check for the limited number of CPUs.&lt;/P&gt;&lt;P&gt;You spoke about THP, please check if it's disabled.&lt;/P&gt;&lt;P&gt;Anyway, I'm pretty sure that the problem are the CPUs, and opening a Case to Splunk Support, surely they will answer in the same way.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 11:38:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574178#M8677</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-09T11:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574185#M8678</link>
      <description>&lt;P&gt;Hello again Giuseppe,&lt;/P&gt;&lt;P&gt;I have an average indexing of 8-10GB per day eventy distributed on my clients/indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;THP is disabled and confirmed via Health Check.&lt;/P&gt;&lt;P&gt;I have checked my Scheduler Activity: Instance dashboards and things seem to be much better. Splunk_CIM with acceleration disabled has decluttered the dashboards and I still don't see any other data model having a skipped search. Since I disabled it, I have zero skipped scheduled searches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will wait a bit more and see how it goes.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Chris&lt;BR /&gt;&lt;BR /&gt;PS: CPU upgrade is being planned soon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But it's better to search for a possible misconfiguration first rather than adding CPUs and hiding the underlying problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 12:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574185#M8678</guid>
      <dc:creator>IoannisG</dc:creator>
      <dc:date>2021-11-09T12:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574187#M8679</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231311"&gt;@IoannisG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the use of the reference hardware is useful even if your system is underused because it's the first notation when you open a Case to Splunk Support.&lt;/P&gt;&lt;P&gt;let me know if you solved.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 12:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574187#M8679</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-09T12:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574900#M8684</link>
      <description>&lt;P&gt;Buon giorno Giuseppe,&lt;/P&gt;&lt;P&gt;I have managed to make my Splunk status green by doing the following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1. Fixing the default tags on Splunk CIM&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=remote* servicesNS/-/-/saved/eventtypes
| search tags=*
| table eai:acl.app, eai:acl.sharing eai:acl.perms.read, title, search, tags, author&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;this search helped me identify which are the tags that I should whitelist in each datamodel. Indexes were already set in macros but tags seemed to be completely wrong.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2. Fixing my ulimits&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The fsize line was missing, which was the one that fixed my open files warning.&lt;/P&gt;&lt;PRE&gt;*  hard  nofile   64000
*  hard  nproc   16000
*  hard  fsize     -1&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;I have checked all my scheduled searches one by one and they were optimized (search window: auto, no real-time searches).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3. Minimized the summary indexing according to needs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Some datamodels were set to create a summary index for a period that I did not need (eg. 1 year). So changing this to a smaller range might have helped too.&lt;/P&gt;&lt;P&gt;Hardware resource consumption was and still seems to be in low levels, but an upgrade has to be performed for sure.&lt;/P&gt;&lt;P&gt;Thanks a lot for your support.&lt;/P&gt;&lt;P&gt;With kind regards,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 10:08:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574900#M8684</guid>
      <dc:creator>IoannisG</dc:creator>
      <dc:date>2021-11-15T10:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk CIM Data Model Acceleration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574902#M8685</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231311"&gt;@IoannisG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you,&amp;nbsp;let me know if you need more help, otherwise, please accept the answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 10:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-CIM-Data-Model-Acceleration/m-p/574902#M8685</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T10:44:46Z</dc:date>
    </item>
  </channel>
</rss>

