Knowledge Management

Delayed/Offset Datamodel Acceleration

bkeif
Path Finder

I have a large set of data that comes in to splunk regularly but on couple days delay. It needs to be accelerated to be usable in our environment but I think If I wanted a 7 day datamodel I would need some way to tell the datamodel to start accelerating at -3d and go back 7 days from there to give the data some time to get in instead of starting now and going back 7 days as data will never be in "now".

Any thoughts / suggestions other than just making a summary index manually?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...