Splunk Enterprise Security

Splunk Common Information Model (CIM): Why is data model acceleration not working for Email data model?

cwilmoth
Path Finder

We are running the latest versions of Splunk Enterprise, Splunk Enterprise Security, and Splunk Common Information Model (CIM) [SA_CIM]. I can enable acceleration for the Email data model, but it never goes past 0% built and always says "Building". I am not having issues with any other data model. If I search for tag=email like the data model constrains to, I get plenty of events (Cisco IronPort source). If I search the data model | datamodel Email search, it returns events. Yet acceleration (which drives the email dashboards) does not work. If I clone the Email model to Email_temp and accelerate the new one, it works fine. What could be the issue here?

Thanks

Craig

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee
0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

Make sure you are making your acceleration setting changes in the Data Model Acceleration Enforcement modular input on your search head. ES overrides any acceleration changes you try to make elsewhere. The Email data model is accelerated by ES by default, so you probably should not need to make changes here unless someone went to this modular input and deaccelerated the model.

Next, you can adjust the settings on the CIM setup for the Email data model to see if tweaking the settings there helps the data model finish building.

0 Karma

cwilmoth
Path Finder

The data model is accelerated. I can go to the Data Model Audit page and see that it is enabled, but it does not build. It is always at 0. When I clone it to a new name, that model builds to completion in about 10 minutes. I can leave the Email model go for days and it never goes past 0.

The scheduler is running the searches for this every five minutes but it looks like it is coming back with zero results every time. I started digging through the acceleration searches and I think I found something. There is a warning from the StringSearchExpander that it is "Unable to find tag email". This tag is specified in the TA_cisco_esa app and has global permissions, so I'm not sure why it can't be "found".

0 Karma

wcwnesta
New Member

Hi cwilmoth:
I met similar problems like you, the data model WEB can not be accelerated. But it works opposite to yours. the WEB completes the accerleration immediately and it shows 'done'. But indeed it did not accelerate anything.

I copy the WEB to WEB2, and it works fine.

Did you solve this problems?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...