Splunk Search

what is the difference between summary indexing and data models?

Day
Engager

Hi 🙂 i'm new hier and i still don't understand the difference between summary indexing and data modeling.

When should I use each? Or which is the best option for optimizing searches?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Day,

they are both ways to accelerate searches when you have to use structured fields (searches using fields, not full text searches.

they both use schedule searches to take events from the raw logs

Data Models use DB tables, instead Summary indexes are standard Splunk indexes containing the extracted fields.

You can accelerate Data Models.

for more infos see at 

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutsummaryindexing

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutdatamodels

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Day,

they are both ways to accelerate searches when you have to use structured fields (searches using fields, not full text searches.

they both use schedule searches to take events from the raw logs

Data Models use DB tables, instead Summary indexes are standard Splunk indexes containing the extracted fields.

You can accelerate Data Models.

for more infos see at 

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutsummaryindexing

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutdatamodels

Ciao.

Giuseppe

ITWhisperer
SplunkTrust
SplunkTrust

It depends on your data and what you are trying to get from it. It also depends on what sort of optimisation you are trying to achieve, e.g. speed, length of SPL, size of configuration data, maintenance overhead, etc.

Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...