Hi @SplunkySplunk , as @inventsekar said, these are thre ways to accelerate searches that runs in a different way and that re to use in different conditions. e.g. I used report acceleration when I ...
See more...
Hi @SplunkySplunk , as @inventsekar said, these are thre ways to accelerate searches that runs in a different way and that re to use in different conditions. e.g. I used report acceleration when I had a dashboard with many real time searches, used by many users: I created an accelerated report that was visualized in the dashboard, in this way I had a near real time dashboard used by many users, that runned only one search. Data Models, are the most efficient solution if you have to search only using predefined fields. Summary indexes are very useful when you want to reduce and structure your logs: e.. if you have the logs from a fireawll (that usually are very many and with many fields not always used!), you can reduce the logs and use the reducted logs for your searches, also on raw (reducted) logs. As me and @inventsekar said, it depends on what is your requirement. Ciao. Giuseppe