Splunk Enterprise Security

Pro's and Con's on Data model Acceleration. Please advise why or why not , should one accelerate them all?


Why should data models all be accelerated? What about the built-in Data Models?

Labels (1)
Tags (1)
0 Karma


I disagree with the premise that all data models should be accelerated.  One should only accelerate the data models one uses.

Pros of acceleration: faster access to data

Cons: additional storage; additional scheduled searches

If this reply helps you, an upvote would be appreciated.
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!