...It looks like the _time field is truncated to have only seconds. Is this according to design for accelerated datamodels? Is there a way to have a _time field in UNIX format with micro seconds?
I have several questions about data architecture that are rooted in CIM datamodels and performance considerations.
Background: We have about 2T of new log data every day. Some sourcetypes get 1...
...onf2014_DavidClawson_Splunk_how to actually use datamodels
Learn How to Design, Build and Manage DataModels
Splunk-6.4.3-SearchReference-Datamodel
I am at a loss those on how to start. I have played around with t...
...d'hoc searches. The problem I see is if I design a datamodel on the first server and accelerate it, I cannot use the benefit of the acceleration from the second server.
Anyone know if there is a way to d...
Hi guys,
one question.
We have a midsize Splunk environement. Data which is delivered to be ingested is increasing.
We need an architecture where we can handle our high p...
In our multisite cluster, we have two sites: site1 and site 2
We are using datamodel acceleration and are facing issues in getting updated accelerated datamodels available in both sites. There i...
I'm not really sure where to put this as there really isn't any publicly viewable feedback on apps anymore (is a public discussion about a splunk supported inappropriate for answers.spk?)
We've b...