Hello,
We are going to setup some reports to use acceleration using Summary Range of 7 days. Question, how often will Splunk behinds the scene keep the data in the 7 days range. Does Splunk accelerate every 5 mins or 10 mins?
Thx
you can specify these settings. But by default, these are specified in the CIM app, datamodels.conf
For example
#####################
## Authentication
#####################
[Authentication]
acceleration = false
acceleration.allow_old_summaries = true
acceleration.cron_schedule = 3-58/5 * * * *
acceleration.earliest_time = -1y
acceleration.manual_rebuilds = true
acceleration.schedule_priority = highest
tags_whitelist = pci,default,insecure,cleartext,privileged,multifactor
And as per crontab.guru
https://crontab.guru/#3-58/5_*_*_*_*
“At every 5th minute from 3 through 58.”
Each CIM datamodels have its own acceleration timings
you can specify these settings. But by default, these are specified in the CIM app, datamodels.conf
For example
#####################
## Authentication
#####################
[Authentication]
acceleration = false
acceleration.allow_old_summaries = true
acceleration.cron_schedule = 3-58/5 * * * *
acceleration.earliest_time = -1y
acceleration.manual_rebuilds = true
acceleration.schedule_priority = highest
tags_whitelist = pci,default,insecure,cleartext,privileged,multifactor
And as per crontab.guru
https://crontab.guru/#3-58/5_*_*_*_*
“At every 5th minute from 3 through 58.”
Each CIM datamodels have its own acceleration timings
Perfect. Thank you!!!