When I restart Splunk, accelerated data in data-model WEB is deleted. I update the WEB, then the model gets the data slowly.
if the Splunk restarted, and the data will be deleted again by the Splunk system.
Any one can help me to solve the problem ? thanks a lot !
PS:I choose to keep the accelerated data-model WEB for 3 months. other data-models such as Network Intrusion work well. When the Splunk restarted, the accelerated data kept well.
↧