Splunk Enterprise

Using Time Series Indexes

shocko
Contributor

We recently upgraded from Splunk Enterprise 6.1.4 to 8.0.5. We collect quite a bit of Windows Performance counters.  I see that time series indexes are available as per this. Being a Splunk part-timer I'd assume it's a no brainier to start using these for performance counter collection? Seems like that's the entire reason they were brought into the product? Do they save on license count?

 

PS: Obviously I might have to modify a few dashboards and queries but I'm OK with that. 

Labels (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...