Hello There.
Even if all the docs and certifications, it's not clear how is the best (or only way) of doing Datamodel Acceleration in a Full Clustered Environment.
We have a Indexer Cluster with 3 Indexers and a Search Head Cluster with 3 Search Heads connected.
They all have the last Splunk version.
Currently, a few datamodel accelerations are not working as intended.
We have them both configured (json) and accelerated (datamodels.conf) in Indexer Cluster and in Search Head Cluster.
In Indexers, all working with their primary copy of the data. In Search Head Cluster it stuck in "Building", and from time to time it stop updating.
All users and searches are done in the Search Head Cluster (99% with a virtual IP).
Regarding Datamodel Acceleration and tstats/pivot accelerated searchs, whats the best practice.
Do we need to declare datamodel (json) in both indexer cluster and search head cluster?
Do we need to accelerate it (datamodels.conf) in both indexer cluster and search head cluster?
Where the data will reside? Only at indexer?
Is it best to schedule update or do it automatically?
Thanks.
↧