Splunk Enterprise Security

Data Models not being accelerated for Enterprise Security in Splunk 6.0.2

lehrfeld
Path Finder

Hi All -
We have an interesting issue that we just discovered. While attempting to get ES dashboards populated we stumbled across the "Data Model Audit" dashboard in ES. It appears from the Acceleration Details pane that none of our DMs are being accelerated properly. They are in various stages of completeness...

For example, our Network_Traffic DM has an earliest of 12/31/1969 20:00:00 and a latest of 05/11/2032 01:17:20. with 1.5% being completed.

Network_Traffic  Splunk_SA_CIM  1-56/5 * * * *  91  12/31/1969 20:00:00  05/11/2032 01:17:20  1  1.5  0.0

I tried to rebuild it last night and the is says 'completed' but I think it is trying to fool me.

Any ideas on how to trouble shoot this type of issue?

Thanks!

Mike

hardikJsheth
Motivator

What amount of data do you have in your SPLUNK?

You can improve performance of data models by performing following tasks:
1) By default all CIM models look through all indexes. If you know that data is coming from specific index, add it in the base search of the data model.

2) There are two tunable nobes, acceleration.earliest_time and acceleration.backfill_time.

Attaching one PPT, which has some explanation on how to optimize Data Model. link text

0 Karma

cesaccenturefed
Path Finder

We also have a similar issue, we have to do a rolling restart very often on our ES search head cluster, Then Data models need to be rebuilt, I don't think that such maintenance would be needed for our es data models. are there any best practices or solutions to keep data models in line?

0 Karma
Get Updates on the Splunk Community!

Set Up More Secure Configurations in Splunk Enterprise With Config Assist

This blog post is part 3 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...