Splunk Search

Will the data model acceleration enabled for the first search head automatically be enabled for the next search head?

AHA-0114
Explorer

We are currently using a Splunk Enterprise environment with one search head and one indexer.
We enabled data model acceleration because the performance of the search became poor as we used the system.
We are planning to increase the number of search heads by one in order to accommodate more users in the future.

Will the data model acceleration enabled for the first search head automatically be enabled for the next search head?
I do not believe that any additional configuration is necessary, especially since the .tsdix file is configured in the indexer, not in the search head.
If there are any settings required to enable data model acceleration for additional search heads, please let me know.

Labels (2)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Depends on what you want to do. If you want to have two completely independent search heads connecting to the same indexer or indexer cluster, you have to set up summary sharing - https://docs.splunk.com/Documentation/Splunk/8.2.4/Knowledge/Sharedatamodelsummaries

One caveat - it might not be specified explicitly in the docs - the acceleration.source_guid parameter must be set on a per datamodel basis - it cannot be inherited from default settings.

If you want to have a search head cluster, the settings are shared across the nodes in the cluster.

View solution in original post

AHA-0114
Explorer

Thank you for your response.
It was very helpful.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Depends on what you want to do. If you want to have two completely independent search heads connecting to the same indexer or indexer cluster, you have to set up summary sharing - https://docs.splunk.com/Documentation/Splunk/8.2.4/Knowledge/Sharedatamodelsummaries

One caveat - it might not be specified explicitly in the docs - the acceleration.source_guid parameter must be set on a per datamodel basis - it cannot be inherited from default settings.

If you want to have a search head cluster, the settings are shared across the nodes in the cluster.

AHA-0114
Explorer

I want to have  two completely independent search heads connecting to the same indexer, so your answer is very helpful.

Thank you for your response.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...