<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the accelerated Data Model performing slow? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329842#M5949</link>
    <description>&lt;P&gt;Is that streaming command equally spread across your indexers, or do you have one or two indexers that are taking longer then others?&lt;/P&gt;

&lt;P&gt;Dispatch stream taking a lot of time could reflect indexer performance issues, especially around I/o. How are your normal searches running? What if you run tstats against the index instead of the DM. &lt;/P&gt;

&lt;P&gt;Circling back to the data model, what kind of events are fitting into the DM? And what’s the base search look like?&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2018 12:53:33 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2018-01-29T12:53:33Z</dc:date>
    <item>
      <title>Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329837#M5944</link>
      <description>&lt;P&gt;I have an accelerated data model which is performing very slow. It takes more than 2 minutes to return just count of events and more than 4 minutes to do any statistical functions. For example below query takes 121 seconds to run:-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|tstats count from datamodel=mydatamodel where (nodename=mydatamodel.logs) (mydatamodel.tag=prod) groupby "mydatamodel.transactionID"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This returned around 4 Million rows after scanning 12 M events. Is there anything I can do to improve the performance. We have a search head cluster with good configuration and around 13 indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 05:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329837#M5944</guid>
      <dc:creator>vaibhavagg2006</dc:creator>
      <dc:date>2018-01-29T05:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329838#M5945</link>
      <description>&lt;P&gt;What are the terms of the acceleration? Is it actually accelerated? You can check on the status of the data model in your Management Console, or in the Data Model Audit Dashboard of CIM (if you're using it..)&lt;/P&gt;

&lt;P&gt;It's worth noting that your accelerated data exists on the indexers, and not on the SHC. If your indexers are facing anytype of I/o, Memory, or CPU contention, then this can effect performance of your data model.&lt;/P&gt;

&lt;P&gt;Additionally, the structure of your data model can also adversely effect performance. Whats the time span youre searching over? If you adjust the timespan down, how does it effect the search performance?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 08:08:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329838#M5945</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2018-01-29T08:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329839#M5946</link>
      <description>&lt;P&gt;Yes, the data model is accelerated for last 30 days. &lt;BR /&gt;
Indexers are ok in terms of resources, this slowness is consistent and query takes same time to run across the day. &lt;BR /&gt;
I am searching for "Yesterday". The event count I mentioned(12 M) is for 1 day. The logs are in key value formatl&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 08:54:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329839#M5946</guid>
      <dc:creator>vaibhavagg2006</dc:creator>
      <dc:date>2018-01-29T08:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329840#M5947</link>
      <description>&lt;P&gt;Did you confirm that the data is actually accelerated via MC or DM Audit Dashboard? This is a key thing to confirm. If your data model acceleration is not completing or working properly, then your tstats search just search against the raw data, which would give you a search time similar to normal search performance.&lt;/P&gt;

&lt;P&gt;Whats the base search of your data models look like? &lt;/P&gt;

&lt;P&gt;Can you check search log and see where the most process time is spent?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 09:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329840#M5947</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2018-01-29T09:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329841#M5948</link>
      <description>&lt;P&gt;Yes, I checked the acceleration is fine.&lt;BR /&gt;
It is taking maximum time in "command.tstats" and then "dispatch.stream.remote". Under "command.tstats" most of the time is taken by "command.tstats.query_tsidx"&lt;BR /&gt;
Just curious what is invocations in the job inspector. It says 623 for "Command.tstats" and around 25 for each indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 11:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329841#M5948</guid>
      <dc:creator>vaibhavagg2006</dc:creator>
      <dc:date>2018-01-29T11:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329842#M5949</link>
      <description>&lt;P&gt;Is that streaming command equally spread across your indexers, or do you have one or two indexers that are taking longer then others?&lt;/P&gt;

&lt;P&gt;Dispatch stream taking a lot of time could reflect indexer performance issues, especially around I/o. How are your normal searches running? What if you run tstats against the index instead of the DM. &lt;/P&gt;

&lt;P&gt;Circling back to the data model, what kind of events are fitting into the DM? And what’s the base search look like?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 12:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329842#M5949</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2018-01-29T12:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329843#M5950</link>
      <description>&lt;P&gt;Yes the streaming command is equally spread. All the indexers and almost taking equal time.&lt;/P&gt;

&lt;P&gt;My base search looks like something below ::&lt;BR /&gt;
"index=idx1 (sourcetype=abc transactionID=&lt;EM&gt;) OR (sourcetype=xyz ("some search string") ) OR (sourcetype=blah (*search string&lt;/EM&gt;))"&lt;/P&gt;

&lt;P&gt;Also i tried to run normal index search vs tstats against accelerated data model for same set of data.&lt;BR /&gt;
The response time is 168 seconds vs 138 seconds.&lt;BR /&gt;
Event count:-19,821,855&lt;/P&gt;

&lt;P&gt;Not able to run tstats against the index as I dont have indexed fields on which I am trying to group by&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329843#M5950</guid>
      <dc:creator>vaibhavagg2006</dc:creator>
      <dc:date>2020-09-29T17:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329844#M5951</link>
      <description>&lt;P&gt;If the datamodel is accelerated, you can use &lt;CODE&gt;summariesonly=t&lt;/CODE&gt; to only search the accelerated data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|tstats summariesonly=t count from datamodel=mydatamodel where (nodename=mydatamodel.logs) (mydatamodel.tag=prod) groupby "mydatamodel.transactionID"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should result in a faster search.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 14:30:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329844#M5951</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-02-07T14:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the accelerated Data Model performing slow?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329845#M5952</link>
      <description>&lt;P&gt;Did you get an answer to your question above as i am also have performance issues with | tstats&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-accelerated-Data-Model-performing-slow/m-p/329845#M5952</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2018-11-02T14:42:53Z</dc:date>
    </item>
  </channel>
</rss>

