All Apps and Add-ons

Can you disable the acceleration of all data models in the Splunk for Palo Alto Networks app?

hou1css
New Member

Hello,

I am trying to disable ALL possible accelerating data models pertaining to the Splunk for Palo Alto Networks app within Splunk Enterprise 6.2.6. I have already disabled the data model acceleration in the GUI and have verified the local datamodels.conf has acceleration disabled but the datamodel_summary directory is being recreated again. I have seen over 600GB in this directory and have no use for the acceleration so i would prefer the storage space over the acceleration.

[pan_endpoint]
acceleration = 0

[pan_wildfire_report]
acceleration = 0

[pan_firewall]
acceleration = 0

Thanks,
Chris

0 Karma

btorresgil
Builder

You can disable acceleration to save disk space. However, the dashboards that come with the app rely on the acceleration, so disabling acceleration will make the dashboards blank (except the Overview dashboard).

A few alternative options:

  1. If you don't use the dashboards or datamodel and only want to parse the Palo Alto Networks data, you can move from the Palo Alto Networks App to the new Palo Alto Networks Add-on. The Add-on has all the parsing capability and works with Splunk Enterprise Security 4.0 and Common Information Model 4.x. But it doesn't have any dashboards or datamodel.

  2. You can upgrade to Palo Alto Networks App version 5.0 which optimizes the datamodel for more efficient performance and disk utilization. This might help because it will use less disk space for the acceleration.

If you choose to upgrade to App version 5.0, please use the upgrade guide:
http://pansplunk.readthedocs.org/en/latest/upgrade.html

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...