Deployment Architecture

In a multisite cluster, how do we make updated accelerated data models available in both sites with no lag?

splunk24
Path Finder

In our multisite cluster, we have two sites: site1 and site 2
We are using data model acceleration and are facing issues in getting updated accelerated data models available in both sites. There is a big lag in updating the data model in both sites.
please help

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

What is the lag you've noticed in your env ? And forwarders send the data to both the sites or to one site only ?

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Per current design, the data models are independently accelerated in each site rather than replicated. So you will notice some lags initially but the system will catch up. We've enhancement requests filed to replicate the data models between sites rather building again.

splunk24
Path Finder

any update on the enhancement requests?

0 Karma

splunk24
Path Finder

thanks for the quick responses mahamed..
could you please elaborate enhancement request in details.. how it can be done

0 Karma

splunk24
Path Finder

so you filed the request with splunk to solve this issue?

0 Karma

splunk24
Path Finder

Hi.. No issue is not with the data coming from forwarders but data model gets accelerated after 5 min and its summary data get stored in parallel to primary bucket in one site .. So when again in next five min data model will accelerate in other site ... How can we ensure that data model accelerated data is same in both site .. And in the next five min at which site data model will accelerated and other site should be in sync

0 Karma

splunk24
Path Finder

please help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...