Splunk Search

Splunk Stream question

chaker
Contributor

I work for energy capture and storage organisation and we were thinking of using Splunk to capture data from our main "Ecto-Containment System". Streams are a key component of our workflow and one of our reps, Spengler, said we shouldn't cross the streams.

I was just curious what happens if you cross the streams?

Tags (1)
0 Karma
1 Solution

dokian
Explorer

It would be bad.

Try to imagine all indexing as you know it stopping instantaneously and every bucket in your indexes exploding at the speed of an accelerated data model.

View solution in original post

woodcock
Esteemed Legend

If you are using Flash for your Indexers, then you will crush all the bugs:

http://www.hitfix.com/whats-alan-watching/review-the-flash-revenge-of-the-rogues-heat-wave-vs-captai...

0 Karma

ppablo
Retired

Hi @chaker

To clarify for other users, but are you referring to the Splunk App for Stream? https://splunkbase.splunk.com/app/1809/ You didn't mention it anywhere in your post.

dokian
Explorer

It would be bad.

Try to imagine all indexing as you know it stopping instantaneously and every bucket in your indexes exploding at the speed of an accelerated data model.

piebob
Splunk Employee
Splunk Employee

alt text

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...