If you’re running Splunk Enterprise Security Suite, you are already leveraging accelerated datamodels to power your detections and altering. However, there may be situations where you want to leverage those same datamodels you already have when running searches on your other search heads. You could enable acceleration on all your search heads, but doing so will result in higher resource consumption due to all the duplication of searches running from each search head to build the same datamodel acceleration(DMA) summaries.
But, there is a better option! Splunk now allows sharing of data model acceleration summaries across search heads, and it’s pretty easy to set up. Here’s how you do it!
1. On the search head that is currently accelerating summaries, identify the datamodels that are currently accelerated that you would like to share. You can view these by going to Settings -> Data Models. You’ll also want to verify the app context for each data model. On a Splunk Enterprise Security (ES) search head, these are typically defined in the Splunk_SA_CIM app.
7. On the new search head, run the following search to confirm that you can access the shared datamodel. If you get results, it means it is working!
8. Repeat the process for other datamodels that you would like to share, making sure you use the same app context on the new search head as where the datamodels are defined on the origin search head.
9. That’s it! All of these datamodels are now shared and available on your new search head.
At this point, you now know how to leverage shared data model acceleration summaries across your Splunk environment. If you need help getting this set up, or want to enable better security alerting with your Splunk data, reach out to us – we’ll be happy to help!
The post Enable Sharing of Datamodel Acceleration Summaries between Search Heads appeared first on Hurricane Labs.
*** This is a Security Bloggers Network syndicated blog from Hurricane Labs authored by Tom Kopchak. Read the original post at: https://hurricanelabs.com/splunk-tutorials/enable-sharing-of-datamodel-acceleration-summaries-between-search-heads/?utm_source=rss&utm_medium=rss&utm_campaign=enable-sharing-of-datamodel-acceleration-summaries-between-search-heads