Getting Data In

How do we convert msidx v1 to msidx v2?

walkerhound
Path Finder

We have been using the metrics store since version 7.0. We notice that version 7.1 has a huge performance improvement. What do we have to do to get the performance improvement on our current metrics? Will that happen automatically with the upgrade to 7.1? Or do we have to create new metrics indexes?

0 Karma
1 Solution

walkerhound
Path Finder

I entered a support case on this one. It turns out that the upgrade will go smoothly. But only the new events in the metrics store will have the performance improvement.

Here is what they say:

"When you upgrade to 7.1.0, only new data is indexed as v2 (i.e. co-located), the existing buckets are still in v1 format and not changed. But you can still search from both v1 and v2 data."

So you'll be able to search your whole index of course, but only new data will be co-located.

View solution in original post

0 Karma

walkerhound
Path Finder

I entered a support case on this one. It turns out that the upgrade will go smoothly. But only the new events in the metrics store will have the performance improvement.

Here is what they say:

"When you upgrade to 7.1.0, only new data is indexed as v2 (i.e. co-located), the existing buckets are still in v1 format and not changed. But you can still search from both v1 and v2 data."

So you'll be able to search your whole index of course, but only new data will be co-located.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...