Reporting

Can I keep accelerated data longer than the raw data?

a212830
Champion

Hi,

I am creating a data model, which is based upon an index with 90 days retention. Can I keep the accelerated data for a longer period of time than the 90 days, or are the tied together?

0 Karma

woodcock
Esteemed Legend

No, the accelerated data is an index on top of the raw data. What you can do is roll up aggregate data into a Summary Index which can be used in almost the same way with almost the same benefits and it is NOT tied to the raw data (except to generate it):

https://docs.splunk.com/Documentation/Splunk/6.6.0/Knowledge/Usesummaryindexing

0 Karma

a212830
Champion

So, the accelerated data (via data model) is not tied to the raw data? My preference is to avoid summary indexing. Seems like the doc is saying the the accelerated data will get removed when the raw data is removed.

0 Karma

woodcock
Esteemed Legend

Your question is "Can I keep it" and my answer is "No", definitely not.

0 Karma

woodcock
Esteemed Legend

But you can keep Summary Index data differently than raw.

0 Karma

davebrooking
Contributor

The Knowledge Manager documentation states

By default, Splunk software creates each data model acceleration summary on the indexer, parallel to the bucket or buckets that cover the range of time over which the summary spans, whether the buckets that fall within that range are hot, warm, or cold. If a bucket within the summary range moves to frozen status, Splunk software removes the summary information that corresponds with the bucket when it deletes or archives the data within the bucket.
So from that I'd say they are tied together.

Dave

a212830
Champion

Thanks. Well, that sucks. Kind of forces my hand to try summary indexing...

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...