Reporting

Can I keep accelerated data longer than the raw data?

a212830
Champion

Hi,

I am creating a data model, which is based upon an index with 90 days retention. Can I keep the accelerated data for a longer period of time than the 90 days, or are the tied together?

0 Karma

woodcock
Esteemed Legend

No, the accelerated data is an index on top of the raw data. What you can do is roll up aggregate data into a Summary Index which can be used in almost the same way with almost the same benefits and it is NOT tied to the raw data (except to generate it):

https://docs.splunk.com/Documentation/Splunk/6.6.0/Knowledge/Usesummaryindexing

0 Karma

a212830
Champion

So, the accelerated data (via data model) is not tied to the raw data? My preference is to avoid summary indexing. Seems like the doc is saying the the accelerated data will get removed when the raw data is removed.

0 Karma

woodcock
Esteemed Legend

Your question is "Can I keep it" and my answer is "No", definitely not.

0 Karma

woodcock
Esteemed Legend

But you can keep Summary Index data differently than raw.

0 Karma

davebrooking
Contributor

The Knowledge Manager documentation states

By default, Splunk software creates each data model acceleration summary on the indexer, parallel to the bucket or buckets that cover the range of time over which the summary spans, whether the buckets that fall within that range are hot, warm, or cold. If a bucket within the summary range moves to frozen status, Splunk software removes the summary information that corresponds with the bucket when it deletes or archives the data within the bucket.
So from that I'd say they are tied together.

Dave

a212830
Champion

Thanks. Well, that sucks. Kind of forces my hand to try summary indexing...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...