...619093900). It looks like the _time field is truncated to have only seconds. Is this according to design for accelerated datamodels? Is there a way to have a _time field in UNIX format with micro seconds?
I have several questions about data architecture that are rooted in CIM datamodels and performance considerations.
Background: We have about 2T of new log data every day. Some sourcetypes get 1...
...onf2014_DavidClawson_Splunk_how to actually use datamodels
Learn How to Design, Build and Manage DataModels
Splunk-6.4.3-SearchReference-Datamodel
I am at a loss those on how to start. I have played around with t...
...d'hoc searches. The problem I see is if I design a datamodel on the first server and accelerate it, I cannot use the benefit of the acceleration from the second server.
Anyone know if there is a way to d...
In our multisite cluster, we have two sites: site1 and site 2
We are using datamodel acceleration and are facing issues in getting updated accelerated datamodels available in both sites. There i...
...t eventually got shipped into Production (with no changes). The server is old and is needs to be evergreened. My question is this: If you could design a new system, what would you go with? I have the p...
Hello Community!
When we do some search in CIM syntax with Splunk 6.6.x , we saw the CIM fields like por example : Al_traffic.xxx and also the basic fields like src_ip , src_port and the Splunk_se...