Getting Data In

Is INDEXED_EXTRACTIONS = json expensive on the indexer?

ddrillic
Ultra Champion

In What are the requirements for a perfect Splunk JSON document?

We spoke about -

INDEXED_EXTRACTIONS = json
category = Structured

Is INDEXED_EXTRACTIONS = json expensive on the indexer? because I'm being told that we should avoid it due to the load it puts on the indexer...

1 Solution

sudosplunk
Motivator

Hi @ddrillic,

In short yes. Please have a look at this article. This guy did some good case study comparing index-time vs search-time extractions.

https://www.hurricanelabs.com/blog/splunk-case-study-indexed-extractions-vs-search-time-extractions

HTH!

View solution in original post

sudosplunk
Motivator

Hi @ddrillic,

In short yes. Please have a look at this article. This guy did some good case study comparing index-time vs search-time extractions.

https://www.hurricanelabs.com/blog/splunk-case-study-indexed-extractions-vs-search-time-extractions

HTH!

ddrillic
Ultra Champion

Very interesting @nittala_surya.

I guess they are saying that -
KV_MODE=JSON on the search heads is equivalent to
INDEXED_EXTRACTIONS=JSON on the indexer side

And the overhead on the SHs is lighter.

Is it right?

0 Karma

sudosplunk
Motivator

Absolutely.

0 Karma

ddrillic
Ultra Champion

Speaking with the sales engineer who explained that in certain cases it can be expensive and in certain cases not. He also said that in case the json document is not valid we can lose data as only the name value pairs are retained and not the raw data. KV_MODE = JSON on the SH and the indexer marks the data as json.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...