Splunk Search

what is the difference between summary indexing and data models?

Day
Engager

Hi 🙂 i'm new hier and i still don't understand the difference between summary indexing and data modeling.

When should I use each? Or which is the best option for optimizing searches?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Day,

they are both ways to accelerate searches when you have to use structured fields (searches using fields, not full text searches.

they both use schedule searches to take events from the raw logs

Data Models use DB tables, instead Summary indexes are standard Splunk indexes containing the extracted fields.

You can accelerate Data Models.

for more infos see at 

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutsummaryindexing

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutdatamodels

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Day,

they are both ways to accelerate searches when you have to use structured fields (searches using fields, not full text searches.

they both use schedule searches to take events from the raw logs

Data Models use DB tables, instead Summary indexes are standard Splunk indexes containing the extracted fields.

You can accelerate Data Models.

for more infos see at 

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutsummaryindexing

https://docs.splunk.com/Documentation/Splunk/9.1.1/Knowledge/Aboutdatamodels

Ciao.

Giuseppe

ITWhisperer
SplunkTrust
SplunkTrust

It depends on your data and what you are trying to get from it. It also depends on what sort of optimisation you are trying to achieve, e.g. speed, length of SPL, size of configuration data, maintenance overhead, etc.

Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...