In the splunk system we developed, we have 2.8 billion records as of now.
The problem is that it's a single configuration (not using idexer/search head yet)
and depending on the search condition, it takes so long for searching the data.
If I update to splunk 7.0, I can see that the search speed may be improved.
First you will need to create a new index that is specifically tuned for metrics data.
This index will use our Metrics Store which provides the ability to ingest and store metric measurements at scale.
Regarding to "a new index that is specifically tuned for metrics data.",
Will I still be able to search the current data after upgrading to 7.0 and creating new index for metrics data?
Thanks so much for your help in advance.
... View more