The Splunk UI reports that the data model is many terabytes in size. Why is it so large? The size is such that I am concerned about the space allocated for my actual data is being consumed.
Did you reduce the default time range of the data model? I believe out of the box, it is set for a year. Also, what is the data volume of your pan logs?
Yes, I have reduced the default time-range.
Conversely, do you think it is appropriate to set the default acceleration to -1y out-of-the-box?