How it works...

Once you accelerate each model, Splunk starts building acceleration summaries behind the scenes for the one-month range that we selected. These summaries are built within the indexes that contain the fields specified in each data model, in this case the main index. The summaries are held in Splunk TSIDX files alongside the buckets of data in the index on the indexers. Splunk runs an internal process to keep these summaries updated every 5 minutes (by default) and runs a maintenance process to clean out old data every 30 minutes.

In this recipe, you accelerated both the data models. However, accelerating data models does use disk space and adds additional overhead and processing, so it is only recommended on large datasets ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.