Knowledge Management

Is it possible to run arbitrary searches that take advantage of accelerated data models without using pivots?


I am looking into possibility of replacing summary indexing with data model acceleration.
I have a number of external, scheduled searches that refer to summary index in a normal manner, such as:
index=my_summary_index whatever I need...

Data Model Acceleration, while sounds promising seems to be limited to this type of query:
| pivot data_model_id object_id ...

Is it possible to somehow use totally arbitrary searches that tap into accelerated data models without using pivots?

0 Karma

Path Finder

The datamodel command allows you to pull events from a datamodel object. You can also use the tstats command to pull stats from a datamodel object.

0 Karma