Reporting

Splunk ES Datamodel Constantly Rebuilding

domenico_perre
Path Finder

Hi All,

I have a problem that has been giving me a bit of grief with ES. Essentially my larger datamodels (Authentication / Network) never seem to get over 10% before restarting at 0%. I am running 2 clustered indexers and a dedicated SH for ES.

I have confirmed that there are no lookup table errors, uninstalled all apps that are not being used, disabled correlation searches that I don't have data for and disabled data models that I don't have data for.

I must admit that I am running VM's with 8 CPUs each idx and ES. When ES is not running, the idxs run at around 3-10% cpu then spike up to 100% when it is started. I know I am technically not supported because the lack of cpu, but would like to know if there is anything else I can look for?

Thx in advance.

1 Solution

domenico_perre
Path Finder

So I will answer my own question.

The issue I had was related to the total time it took to build a Datamodel. As it was attempting to build for over an hour it would rerun and wipe the data model. I edited the datamodels.conf relating to the DMs that were taking the longest with the following

acceleration.max_time = 86400

This is probably due to my underspecced indexers but was an adequate solution imo.

Most DMs are 100% completed and CPU has dropped 🙂

View solution in original post

domenico_perre
Path Finder

So I will answer my own question.

The issue I had was related to the total time it took to build a Datamodel. As it was attempting to build for over an hour it would rerun and wipe the data model. I edited the datamodels.conf relating to the DMs that were taking the longest with the following

acceleration.max_time = 86400

This is probably due to my underspecced indexers but was an adequate solution imo.

Most DMs are 100% completed and CPU has dropped 🙂

domenico_perre
Path Finder

Even if someone could,tell me where data model operations log to I could look into that.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...