Dashboards & Visualizations

Percent complete for data models

awmorris
Path Finder

If a an accelerated data model is 80% complete, what does that ACTUALLY mean? Does it mean I have 80% of the events? 80% of the time? 80% of the data?

Almost half my data models are not keeping up at even close to 100% but i can't figure out what is actually "missing" from the data models.

Tags (1)
0 Karma

awmorris
Path Finder

I'll refine my question to try to drive out the answer I need... can someone give me a SPL formula I can use to self calculate the percent complete. If I can get the formula, that will tell me the information I am trying to discover. My problem is my data model is at 55% complete and heading south every day.

0 Karma

gjanders
SplunkTrust
SplunkTrust

I have a couple of dashboards in Alerts for Splunk Admins for this purpose, git links here and here

Do they help? As you can see they are based on a conf presentation that is worth watching!

0 Karma

tom_frotscher
Builder

Hi,

i do not know the exact definition of this field. But for my experience, it says that in your case 80% of your configured summary range is accelerated (for example 32 out of 40 days).

If this value is not progressing, you might have to many running searches. The data model acceleration is driven by scheduled searches in the background. Can you check the management console for skipped scheduled searches?

Greetings,

Tom

0 Karma

awmorris
Path Finder

Thanks but that's not it. I have events for each of the 30 days in the data model.

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...