Splunk Enterprise Security

Does Enterprise Security automatically re-enable data model acceleration?

Lowell
Super Champion

I'm trying to disable acceleration on a data model that's consuming a massive amount of memory on the indexers. All the correlation searches for this data model are disabled, and I'm fine with some of the related dashboards being slow or unavailable (if they use tstats, for example).

I disabled acceleration and it was re-enabled a few hours later. So far no one has confessed to re-enabling it.

So I'm wondering if there's some automatic "protect-you-from-yourself" functionality that turns acceleration back on automatically.

1 Solution

Lowell
Super Champion

Yes, ES will automatically override DM acceleration state. This can be controlled under the "Data Inputs" manager UI. There's an entry called "Data Model Acceleration Enforcement" where this can be controlled on a more permanent basis.

This is controlled via modular input called dm_accel_settings that will enforce these settings.

View solution in original post

Lowell
Super Champion

Yes, ES will automatically override DM acceleration state. This can be controlled under the "Data Inputs" manager UI. There's an entry called "Data Model Acceleration Enforcement" where this can be controlled on a more permanent basis.

This is controlled via modular input called dm_accel_settings that will enforce these settings.

koshyk
Super Champion

do you know how to change it in a Clustered ES system? (coz via its not changeable)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...