Monitoring Splunk

How to calculate disk space for Data Model Acceleration?

payal23
Path Finder

How to calculate disk space by all indexers used by the data model acceleration?

0 Karma

codebuilder
Influencer

The total size of your datamodel acceleration is presented nicely by the web UI on any search head member in your cluster.
Settings > Datamodels > All >

Then expand the row for the datamodel you want to find info about. The "Size on Disk" is what I believe you are looking for, and this number represents the total size, across all indexers.

alt text

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
Influencer

Did this solution work for you?

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

payal23
Path Finder

I used | rest "/services/admin/introspection--disk-objects--summaries?count=-1" | stats sum(total_size) by name | addcoltotals

But I can see two datamodel for the same name

  1. DataModel_A
  2. DataModel_A.ObjectName

I can see DataModel_A taking space which is shown in the UI disk space.
DataModel_A.ObjectName is taking a huge space. But the same i cannot see in any of the path in the server.

Can aynone help me in this?

0 Karma

p_gurav
Champion

Try adding | search type="data_model_acceleration" to search query

0 Karma

payal23
Path Finder

yes.. it is listing all.. still. I want to understand what is that .Objectname file and in the server where it resides and consuming space

0 Karma

p_gurav
Champion

On the indexers, It is stored in $SPLUNK_HOME/var/lib/splunk/index_name/datamodel_summary, where "index_name" is the name of the index from which the datamodel is collecting data.

0 Karma

payal23
Path Finder

yes.. checked the same.. When i check inside datamodel_summary it is taking 20 GB. But I can see there is an increase of 200 GB in the server. So, when i check with the rest query which i posted in the question, it is showing 200 GB, but the same i cannot see in the server.

So, I am confused!

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...