Splunk Search

Splunk Stream question

chaker
Contributor

I work for energy capture and storage organisation and we were thinking of using Splunk to capture data from our main "Ecto-Containment System". Streams are a key component of our workflow and one of our reps, Spengler, said we shouldn't cross the streams.

I was just curious what happens if you cross the streams?

Tags (1)
0 Karma
1 Solution

dokian
Explorer

It would be bad.

Try to imagine all indexing as you know it stopping instantaneously and every bucket in your indexes exploding at the speed of an accelerated data model.

View solution in original post

woodcock
Esteemed Legend

If you are using Flash for your Indexers, then you will crush all the bugs:

http://www.hitfix.com/whats-alan-watching/review-the-flash-revenge-of-the-rogues-heat-wave-vs-captai...

0 Karma

ppablo
Retired

Hi @chaker

To clarify for other users, but are you referring to the Splunk App for Stream? https://splunkbase.splunk.com/app/1809/ You didn't mention it anywhere in your post.

dokian
Explorer

It would be bad.

Try to imagine all indexing as you know it stopping instantaneously and every bucket in your indexes exploding at the speed of an accelerated data model.

piebob
Splunk Employee
Splunk Employee

alt text

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...