Reporting

Data Model extend Summary Range: Should I rebuild or update do nothing?

oshirnin
Path Finder

Hello, everybody!

I have accelerated Data Model «DA Host OS» set with 7 Days Summary Range and it works as expected:

alt text

alt text

What if now I need to extend this Summary Range to 1 Month and later to 3 Months - after I change the setting and click «Save» should I do anything else? I am especially interested if I should completely rebuild the summaries or Splunk will reuse already calculated 7 days summaries and start calculate and store newly summaries to 1-3 Months depth? I have Backfill Range set to Match Summary Range.

alt text

I checked the docs https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/Knowledge/Managedatamodels «Rebuild a summary for an accelerated data model» and «Update summary metrics for an accelerated data model» but it is still not quite clear what should I do in my case.

Thanks for the advice!

0 Karma
1 Solution

woodcock
Esteemed Legend

Yes, you need to account for the significant increase in disk usage that extending the range incurs or you may cause data loss by freezing buckets early. It will keep what it has already and work farther backwards.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Yes, you need to account for the significant increase in disk usage that extending the range incurs or you may cause data loss by freezing buckets early. It will keep what it has already and work farther backwards.

0 Karma

oshirnin
Path Finder

Thank you. I will give it a try!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...