Splunk Dev

data model acceleration

sarit_s
Communicator

Hello,

I have data model that i want to change the acceleration time to all time.

since im working with kubernetece the change has to be in the config files directly and not through the ui.

i saw in the documentation that empty string for 

acceleration.earliest_time

means all time

but when i change this field to be empty, the configuration in the ui changed to be 1 day instead of all time as it should.

 

any ideas ?

thanks 

richgalloway
SplunkTrust
SplunkTrust

Searching All Time rarely is a good idea, especially for datamodels.  The goal of DMA is to make accessing your data faster in routine searches.  One-off and non-routine searches usually can wait the extra time it takes to gather the data.  Otherwise, you're putting extra work on your system to search (and store) more than is necessary.

What is the use case for having All Time data accelerated?

---
If this reply helps you, Karma would be appreciated.
0 Karma

sarit_s
Communicator

Well, its not permanent 

we want to run some statistics over data older than a year

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...