Splunk Search

Splunk Data Fabric Search(DFS) basics

inventsekar
SplunkTrust
SplunkTrust

Data Fabric Search - DFS overview
Data Fabric Search (DFS) is the new search platform that leverages the distributed processing power of external compute engines (Apache Spark Core) to broaden the scope and capability of the Splunk Enterprise.
Update - The document link -
https://docs.splunk.com/Documentation/DFS/7.3.0/DFS/Overview

Hi All, ...As i read this from the Splunk DFS docs, i feel like - instead of using a Splunk Search Head Cluster(SHC), this DFS concepts will be using the external compute engines(Apache Spark Core) and produce the similar results, thus by reducing the Search heads count, thus the reduced cost and time. may i know if this is correct?

(DFS/"Data Fabric Search" tags are not available yet, it seems only admins can create the tags)

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

tchavez_splunk
Splunk Employee
Splunk Employee

Splunk DFS 1.1 does not yet support all of the SPL that comes with Splunk Enterprise. But for what it does support, it can offload onto the Spark cluster and run big jobs faster. Today's release of Splunk DFS Manager app v1.2 https://splunkbase.splunk.com/app/4745/ in Splunkbase makes managing the Spark cluster quite easy if you're already running Splunk 8.0.x or later. And with Splunk 8.0.x, you get free vCPU credits to use with Splunk DFS for licenses >1Tb.

burwell
SplunkTrust
SplunkTrust

Yes the computation for things like stats can be done on the Spark nodes instead of the indexers. Even better many many events can be worked on. More than possible in Splunk today.

The slides from last year's Splunk user conference on DFS might help you.

You can search for data fabric search on conf.splunk.com

Here's the link from that site

https://static.rainfocus.com/splunk/splunkconf18/sess/1522100899799001shWk/finalPDF/FN1184%20-%20Dee...

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...