Reporting

Datamodels getting rebuild after after attaching it to new Search Head.

AKG1_old1
Builder

Hello,

We are trying to move from Single node installation to multinode/Distributed Search Installation(1SH and 2 Indexer) - Not clustered

for this we have copied full Production installation and attached it as Indexer in new distributed Search Setup.

Issue is datamodels are getting rebuild. Is this expected ?

we have many big datamodels and don't want them to rebuild if possible. It takes 12hrs+ to rebuild and machine is swamped as its heavy process.

FYI : When I copied Full Prod as Indexer I have trimmed down our App (having datamodels)

Kept these files in App and removed everything else. Not sure if there is any other files needed to stop rebuilding datamodels.
app.conf
datamodels.conf
eventtypes.conf
indexes.conf
props.conf
transforms.conf

Thanks

0 Karma

ivanreis
Builder

This is the expected datamodel behavior. Every time you have to edit the datamodel, the acceleration have to be disabled and when you enable it again, splunk will create the summary index to accelerate the output results from datamodel and it is based on the amount of data you have on the datamodel.

for further information check these documents -> https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/Managedatamodels

0 Karma

AKG1_old1
Builder

Hi,

I understant that if we have to edit datamodel accelration need to be disabled. but in my case I haven't edit datamodels, its exact same. Even I have tried attaching my full installation as Indexer to another SH without changing anything. Still its rebuilding the datamodels.

Just wanted to know if there is any way to move Indexer to another setup without rebuilding datamodels.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...