Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to configure Data Model Acceleration when there are multiple search heads

$
0
0
TL;DR: In a site with multiple search heads; do I need to configure Data Model Acceleration on each and every search head? IF the answer is yes, then can someone ELI5 how the jobs governing DMA run amongst multiple SH without causing conflicts? ENVIRONMENT: Search Head Cluster with 3 members; one standalone search head; and 10 indexer peers (no clustering). Our goal was to install the Palo Alto App on all search heads so that we could leverage its dashboards regardless of whether user is on SHC, or on standalone. ISSUE: Palo Alto app was installed on all search heads specified above. Currently, the data model acceleration is configured on the search head cluster for Palo Alto data models, with 7 day acceleration range. DMA is **NOT** set on the standalone. Search head cluster members can leverage the Palo Alto dashboards, but the standalone does not populate the dashboards with any data. Maybe I'm chasing a red herring, but the only configuration difference I'm aware of, is DMA not being enabled on the standalone SH. I've confirmed that indexer peers have datamodel_summary folders for the indexes associated with Palo Alto data. No indexing is being done locally on the search heads.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>