I want to create a datamodel which will hold aggregated usage. I have a data model currently that holds usage values, I am running complex "group by" and sum to get usage values which is affecting the performance and most jobs are unable to run. I attempted to create a new datamodel by adding this search as root search but I do not know how to use it.
What and how would you suggest I get this done best?
Have you considered a summary index
?
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing