Hi slr
The scheduled search should pick up the new data even if it is from yesterday but the data model acceleration will have already run and it will not backfill. As the app was never designed for batch file delivery I have not tested this scenario before. In this case I also believe you need to modify the schedule for the DM acceleration. This is done by modifying the file datamodels.conf which can be found here:
SPLUNK_HOME/etc/apps/SplunkAppForWebAnalytics/local/datamodels.conf
[Web]
acceleration = 1
acceleration.cron_schedule = 2,12,22,32,42,52 * * * *
acceleration.cron_schedule = 0 21 * * *
I commented out the original schedule (every 10 minutes) to now run every day at 9pm. Change the schedule to about one hour after your batch file is dropped in.
Can you try this?
j
... View more