Splunk Search

Splunk Data Fabric Search(DFS) basics

inventsekar
SplunkTrust
SplunkTrust

Data Fabric Search - DFS overview
Data Fabric Search (DFS) is the new search platform that leverages the distributed processing power of external compute engines (Apache Spark Core) to broaden the scope and capability of the Splunk Enterprise.
Update - The document link -
https://docs.splunk.com/Documentation/DFS/7.3.0/DFS/Overview

Hi All, ...As i read this from the Splunk DFS docs, i feel like - instead of using a Splunk Search Head Cluster(SHC), this DFS concepts will be using the external compute engines(Apache Spark Core) and produce the similar results, thus by reducing the Search heads count, thus the reduced cost and time. may i know if this is correct?

(DFS/"Data Fabric Search" tags are not available yet, it seems only admins can create the tags)

0 Karma

tchavez_splunk
Splunk Employee
Splunk Employee

Splunk DFS 1.1 does not yet support all of the SPL that comes with Splunk Enterprise. But for what it does support, it can offload onto the Spark cluster and run big jobs faster. Today's release of Splunk DFS Manager app v1.2 https://splunkbase.splunk.com/app/4745/ in Splunkbase makes managing the Spark cluster quite easy if you're already running Splunk 8.0.x or later. And with Splunk 8.0.x, you get free vCPU credits to use with Splunk DFS for licenses >1Tb.

burwell
SplunkTrust
SplunkTrust

Yes the computation for things like stats can be done on the Spark nodes instead of the indexers. Even better many many events can be worked on. More than possible in Splunk today.

The slides from last year's Splunk user conference on DFS might help you.

You can search for data fabric search on conf.splunk.com

Here's the link from that site

https://static.rainfocus.com/splunk/splunkconf18/sess/1522100899799001shWk/finalPDF/FN1184%20-%20Dee...

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...