Hello, Splunk Masters
I'm SPlunk Newbie. i have a question.
I am currently collecting Fortigate logs.
I checked because the total disk space was too large compared to the actual total index usage, and it was taking up additional space equal to the amount stored in the index as datamodel_summary.
I'd like to delete this data. Is there a way to do so? I'm also wondering if deleting this data will significantly affect data retrieval.
Thanks.
Hi there,
you probably have Data model acceleration enabled, you can disable it. Just have a read here https://help.splunk.com/en/splunk-cloud-platform/common-information-model/6.1/using-the-common-infor...
Hope this helps ...
Cheers, MuS