Hi Team,
We are using splunk enterprises.
We can ingest data in below two formats.
1. json
2. text like "2021-02-08 16:40:39.385 INFO [main ] com.XX.program.Sample:publishToKafka - paymentId:12344 received"
Wanted to know performance wise which one is preferred. So while doing a query against the data which one will take less time.
Thanks
santos
IMO, raw text is much easier to work with.