This app is archived. Learn more
This app contains a search that checks each CIM 'datamodel' that is both 'enabled' and 'accelerated', runs its 'constraint'/'base-search' against all data to see what 'index'/'sourcetype' pairs have appropriately-tagged events, and compares that against the current 'macro' definition. If they differ, the suggested change is shown in the "definition_data" field. There could be a difference because some data is no longer present and the macro could/should "shrink" or because there is new data and the macro could/should "expand" or perhaps you no longer have any data coming into Splunk that is tagged for your datamodel. In the latter case, you need to investigate and if the data is still there, get it tagged correctly and if not, get it put back in, or if not, unaccelerate the datamodel. Use the "URL" field (cut & paste to browser) to jump directly to edit any datamodel's index macro.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources