Reporting

Data Model extend Summary Range: Should I rebuild or update do nothing?

oshirnin
Path Finder

Hello, everybody!

I have accelerated Data Model «DA Host OS» set with 7 Days Summary Range and it works as expected:

alt text

alt text

What if now I need to extend this Summary Range to 1 Month and later to 3 Months - after I change the setting and click «Save» should I do anything else? I am especially interested if I should completely rebuild the summaries or Splunk will reuse already calculated 7 days summaries and start calculate and store newly summaries to 1-3 Months depth? I have Backfill Range set to Match Summary Range.

alt text

I checked the docs https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/Knowledge/Managedatamodels «Rebuild a summary for an accelerated data model» and «Update summary metrics for an accelerated data model» but it is still not quite clear what should I do in my case.

Thanks for the advice!

0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, you need to account for the significant increase in disk usage that extending the range incurs or you may cause data loss by freezing buckets early. It will keep what it has already and work farther backwards.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Yes, you need to account for the significant increase in disk usage that extending the range incurs or you may cause data loss by freezing buckets early. It will keep what it has already and work farther backwards.

0 Karma

oshirnin
Path Finder

Thank you. I will give it a try!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...