Reporting

What is the data model acceleration default cron schedule?

the_wolverine
Champion

I have data model acceleration enabled and have seen that the data model is not keeping up with the raw data (my dashboards populated by tstats are not showing recent data and can be behind by 1 hour). The datamodels.conf stanzas do not contain a cron. So I'm wondering if there is a default schedule is being used -- and if so -- what is is that schedule?

According to data models.conf.spec:

acceleration.cron_schedule = <cron-string>
* Cron schedule to be used to probe/generate the column stores for this data model

Should I set up a cron to run every minute? Every 5 minutes? What is the suggested schedule?

MuS
SplunkTrust
SplunkTrust

Hi the_wolverine,

the default interval is 5 minutes, where Splunk runs a search to update existing data model summaries. It runs a maintenance process every 30 minutes to remove old, outdated summaries. See the docs http://docs.splunk.com/Documentation/Splunk/6.2.4/Knowledge/Acceleratedatamodels#After_you_enable_ac...

Before decreasing the interval; I would check if the data model acceleration summary search runs without error and on time, see the docs on this http://docs.splunk.com/Documentation/Splunk/6.2.4/Knowledge/Acceleratedatamodels#How_Splunk_Enterpri...

Hope this helps ...

cheers, MuS

somesoni2
Revered Legend

As per documentation, it's getting updated every 5 min. See the 2nd para from below link.

http://docs.splunk.com/Documentation/Splunk/6.2.4/Knowledge/Acceleratedatamodels#After_you_enable_ac...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...