All Apps and Add-ons

Should the Splunk Common Information Model Add-on go onto indexers only, or should it be installed on forwarders and search heads too?

pj_0b
Engager
1 Solution

LukeMurphey
Champion

Install it on your search heads.

It is important that you don't install it on indexers because you can cause the indexers to do double work accelerating the data if you enable data-model acceleration.

If you have it on the search head only, the search head will request acceleration to the indexers and the indexers will begin accelerating the data on behalf of the search-head. If you have the CIM app on the indexers too, then the indexers will accelerate the data for the search head and they will attempt to accelerate if for themselves (they won't recognize the accelerated data already exists since the search head requested it).

View solution in original post

LukeMurphey
Champion

I'm going to follow-up and make sure that the docs cover this more clearly. Looking at the docs now, this isn't clear at all. Good question.

0 Karma

LukeMurphey
Champion

Install it on your search heads.

It is important that you don't install it on indexers because you can cause the indexers to do double work accelerating the data if you enable data-model acceleration.

If you have it on the search head only, the search head will request acceleration to the indexers and the indexers will begin accelerating the data on behalf of the search-head. If you have the CIM app on the indexers too, then the indexers will accelerate the data for the search head and they will attempt to accelerate if for themselves (they won't recognize the accelerated data already exists since the search head requested it).

LukeMurphey
Champion

I submitted a request to get the docs updated. They are now updated to indicate where to put the app: http://docs.splunk.com/Documentation/CIM/4.1.0/User/Install

acharlieh
Influencer

I'll admit I'm not entirely sure this is correct, because I'm not using the CIM just yet. Anyways, if you follow the documentation link from the CIM download page you'll find a document on "Use the CIM to normalize data at search time". That doc says:

If you haven't already done so, get your data into Splunk Enterprise. Do not be concerned about making your data conform to the CIM in the parsing or indexing phase. You normalize your data to be CIM compliant at search time

This leads me to believe that you want to install the CIM on search heads not indexers or forwarders.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...