Splunk Enterprise Security

Pro's and Con's on Data model Acceleration. Please advise why or why not , should one accelerate them all?

SamHTexas
Builder

Why should data models all be accelerated? What about the built-in Data Models?

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I disagree with the premise that all data models should be accelerated.  One should only accelerate the data models one uses.

Pros of acceleration: faster access to data

Cons: additional storage; additional scheduled searches

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...