Summary
In this chapter, we introduced and provided a definition of Splunk's data models, pivots (along with pivot elements and filters) as well as sparklines. By going through the given simple examples, the reader has hopefully grasped the power of these features.
Although Splunk has always performed well, version 7.0 added optimizations to its core modules, which has led to speed up improvement to 20 times against accelerated log data (tstats), and speed up improvement to 200 times against non-accelerated log or event data when querying metrics. There is also considerably less usage of resources with real-time metrics queries. Although these improvements may depend upon specific environments, you should expect to see a visible improvement ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access