All Apps and Add-ons

Palo Alto Networks App for Splunk data model frequently consumes too much space on disk.

the_wolverine
Champion

Even for small time ranges like -1d, the PAN data model consumes too much space on disk amounting to hundreds of GBs and into the TBs when the acceleration was configured to -30d.

0 Karma

btorresgil
Builder

Hi Wolverine,

The acceleration for the datamodel will take up different amounts of space for different environments, depending on the log ingestion rate, type of logs and traffic, number of firewalls and their configurations, etc.

The latest version of the Splunk App (v5.0.0) is more efficient in datamodel acceleration performance and space usage on disk. Try upgrading to version 5.0.0 or higher and re-build the acceleration to get the benefits.

Use the upgrade guide to upgrade to App version 5.0.0:
http://pansplunk.readthedocs.org/en/latest/upgrade.html

If you need the acceleration to take even less space on disk after the upgrade, you can remove fields from the datamodel that you don't need or care about. Note that if you remove a field that is used by a dashboard, that panel in the dashboard might not work. But the dashboards are there to be modified to suit your needs also.

Best regards,
-Brian

0 Karma
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...