Splunk Search

Question about the metrics index in Splunk 7.0.0 and search efficiency

ako_y
New Member

In the splunk system we developed, we have 2.8 billion records as of now.

The problem is that it's a single configuration (not using idexer/search head yet)
and depending on the search condition, it takes so long for searching the data.

If I update to splunk 7.0, I can see that the search speed may be improved.


First you will need to create a new index that is specifically tuned for metrics data.
This index will use our Metrics Store which provides the ability to ingest and store metric measurements at scale.


Regarding to "a new index that is specifically tuned for metrics data.",
Will I still be able to search the current data after upgrading to 7.0 and creating new index for metrics data?

Thanks so much for your help in advance.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

After you upgrade to 7.0 your existing data will be unchanged. It will remain in its current index. The new index will be for metrics data onboarded after the upgrade. There is no way to transfer data from one index to another as metrics indexes are very different from event indexes.

See the Metrics manual (http://docs.splunk.com/Documentation/Splunk/7.0.0/Metrics/Overview) for more information about metrics.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...