Splunk Search

Splunk Data Fabric Search(DFS) basics

inventsekar
Ultra Champion

Data Fabric Search - DFS overview
Data Fabric Search (DFS) is the new search platform that leverages the distributed processing power of external compute engines (Apache Spark Core) to broaden the scope and capability of the Splunk Enterprise.
Update - The document link -
https://docs.splunk.com/Documentation/DFS/7.3.0/DFS/Overview

Hi All, ...As i read this from the Splunk DFS docs, i feel like - instead of using a Splunk Search Head Cluster(SHC), this DFS concepts will be using the external compute engines(Apache Spark Core) and produce the similar results, thus by reducing the Search heads count, thus the reduced cost and time. may i know if this is correct?

(DFS/"Data Fabric Search" tags are not available yet, it seems only admins can create the tags)

0 Karma

tchavez_splunk
Splunk Employee
Splunk Employee

Splunk DFS 1.1 does not yet support all of the SPL that comes with Splunk Enterprise. But for what it does support, it can offload onto the Spark cluster and run big jobs faster. Today's release of Splunk DFS Manager app v1.2 https://splunkbase.splunk.com/app/4745/ in Splunkbase makes managing the Spark cluster quite easy if you're already running Splunk 8.0.x or later. And with Splunk 8.0.x, you get free vCPU credits to use with Splunk DFS for licenses >1Tb.

burwell
SplunkTrust
SplunkTrust

Yes the computation for things like stats can be done on the Spark nodes instead of the indexers. Even better many many events can be worked on. More than possible in Splunk today.

The slides from last year's Splunk user conference on DFS might help you.

You can search for data fabric search on conf.splunk.com

Here's the link from that site

https://static.rainfocus.com/splunk/splunkconf18/sess/1522100899799001shWk/finalPDF/FN1184%20-%20Dee...

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...