Hello,
I was wondering if a new event time-generated 1 month ago but indexed today (with the correct _time, meaning "a month ago") will be accelerated by the Summarization process?
Or is there a way to change the earliest time in the Summarization search for the Data Model Acceleration?
Thanks
Perhaps this will help. https://docs.splunk.com/Documentation/Splunk/8.1.0/Knowledge/Acceleratedatamodels
Whether or not a particular event is included in a DMA depends on the summarization range of the DM. If the range goes back at least a month then a new event dated a month ago will be included.
Hello
Yes, assuming the range is at least a month big.
So that means the summarize search will have a default of "earliest" windows as 1 month? Because the event will be in a bucket named with epoch time of the event (i.e. <latest_event_epoch>_<earliest_event_epoch>_id). So the summarization search need to be able to search into that bucket.
Is there a documentation talking about this?
Are you looking for documentation about how datamodel acceleration finds events that arrived a month late? There isn't anything that specific.
I was just thinking about some docs describing how the summarization search works and how it can be tuned.
Perhaps this will help. https://docs.splunk.com/Documentation/Splunk/8.1.0/Knowledge/Acceleratedatamodels
Hello,
Yes I found this sentence : "This method of summary building also ensures that late-arriving data is summarized without complication."
But without real explanation.