...It looks like the _time field is truncated to have only seconds. Is this according to design for accelerated datamodels? Is there a way to have a _time field in UNIX format with micro seconds?
I have several questions about data architecture that are rooted in CIM datamodels and performance considerations.
Background: We have about 2T of new log data every day. Some sourcetypes get 1...
...onf2014_DavidClawson_Splunk_how to actually use datamodels
Learn How to Design, Build and Manage DataModels
Splunk-6.4.3-SearchReference-Datamodel
I am at a loss those on how to start. I have played around with t...
Hello, I have been working on Splunk for a few months now, and we are using Splunk mainly for Cyber Security monitoring. I am wondering with regards to datamodel (CIM) should I create separate data...
...ermainan ingin mencoba games online terbaik di tahun 2024 anda bisa mencobanya sekarang hanya di situs hitslot dengan design dan serta event terbaik
Hi everyone, I am currently working with creating datamodels for Splunk App. For this app, I am planning to design one main Dataset, with multiple child datasets. These child Datasets, are at the e...
In our multisite cluster, we have two sites: site1 and site 2
We are using datamodel acceleration and are facing issues in getting updated accelerated datamodels available in both sites. There i...
Hi guys,
one question.
We have a midsize Splunk environement. Data which is delivered to be ingested is increasing.
We need an architecture where we can handle our high p...