Splunk Search

what is the difference between summary indexing and data models?

Day
Engager

Hi 🙂 i'm new hier and i still don't understand the difference between summary indexing and data modeling.

When should I use each? Or which is the best option for optimizing searches?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Day,

they are both ways to accelerate searches when you have to use structured fields (searches using fields, not full text searches.

they both use schedule searches to take events from the raw logs

Data Models use DB tables, instead Summary indexes are standard Splunk indexes containing the extracted fields.

You can accelerate Data Models.

for more infos see at 

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutsummaryindexing

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutdatamodels

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Day,

they are both ways to accelerate searches when you have to use structured fields (searches using fields, not full text searches.

they both use schedule searches to take events from the raw logs

Data Models use DB tables, instead Summary indexes are standard Splunk indexes containing the extracted fields.

You can accelerate Data Models.

for more infos see at 

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutsummaryindexing

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutdatamodels

Ciao.

Giuseppe

ITWhisperer
SplunkTrust
SplunkTrust

It depends on your data and what you are trying to get from it. It also depends on what sort of optimisation you are trying to achieve, e.g. speed, length of SPL, size of configuration data, maintenance overhead, etc.

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...