Deployment Architecture

what is data in /opt/splunk/var/lib/splunk/msad/datamodel_summary

aasabei
Loves-to-Learn Lots

Hi everyone,

  "/opt/splunk/var/lib/splunk/msad/datamodel_summary/     " is taking up the most space on the root volume   120G , and last modified date was 2 years ago. can i delete them  ? 

 

Best,

Amir

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
That directory is where the data from the msad index is stored data models. Since AD generates a lot of events, it's not surprising that DM is so large.
If you have accelerated data models that reference index=msad and you use that DM then you should not touch the directory.
If no DMs use the msad index then I'm surprised the data hasn't aged out under the index's retention settings.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...