Getting Data In

How do we convert msidx v1 to msidx v2?

walkerhound
Path Finder

We have been using the metrics store since version 7.0. We notice that version 7.1 has a huge performance improvement. What do we have to do to get the performance improvement on our current metrics? Will that happen automatically with the upgrade to 7.1? Or do we have to create new metrics indexes?

0 Karma
1 Solution

walkerhound
Path Finder

I entered a support case on this one. It turns out that the upgrade will go smoothly. But only the new events in the metrics store will have the performance improvement.

Here is what they say:

"When you upgrade to 7.1.0, only new data is indexed as v2 (i.e. co-located), the existing buckets are still in v1 format and not changed. But you can still search from both v1 and v2 data."

So you'll be able to search your whole index of course, but only new data will be co-located.

View solution in original post

0 Karma

walkerhound
Path Finder

I entered a support case on this one. It turns out that the upgrade will go smoothly. But only the new events in the metrics store will have the performance improvement.

Here is what they say:

"When you upgrade to 7.1.0, only new data is indexed as v2 (i.e. co-located), the existing buckets are still in v1 format and not changed. But you can still search from both v1 and v2 data."

So you'll be able to search your whole index of course, but only new data will be co-located.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...