I'm under splunk 5, and having a lot of scheduled Job, simply making heavy spath and rex jobs, to store my Data in kv, instead of xml, because otherwise searching is to slow...
At the moment, I use summmary_index, which have some drawbacks
- if something happens during search, summary_index is not complete
- I can't specify the sourcetype
- ...
It seems to me, that the new accelaration, seems to be stable and offer a more robust way to prepare Data, but I've seen that you need a | stats, timechart to use it ?
Is there a way to use acceleration anyway for splitting xml files ?
Otherwise is there a better way to do this in Splunk 6 than with summery_index ?
... View more