Summary

In this chapter, we introduced and provided a definition of Splunk's data models, pivots (along with pivot elements and filters) as well as sparklines. By going through the given simple examples, the reader has hopefully grasped the power of these features.

Although Splunk has always performed well, version 7.0 added optimizations to its core modules, which has led to speed up improvement to 20 times against accelerated log data (tstats), and speed up improvement to 200 times against non-accelerated log or event data when querying metrics. There is also considerably less usage of resources with real-time metrics queries. Although these improvements may depend upon specific environments, you should expect to see a visible improvement ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.