Summary
This chapter focused on improving search performance. We looked at different conceptual ways of storing data, including table datasets, lookup datasets, and datamodel datasets. All of these concepts, when used correctly, can increase Splunk’s efficiency. We also looked at examples of each of these concepts. We explored how data is stored on disk when organized in data models and we introduced the tstats
command for searching data models. We looked at the CIM and explored its various datasets and features. Finally, we highlighted 20 different ways we can improve Splunk performance, including from an administrative point of view and when searching.
In the next chapter, we will look at some newly introduced Splunk concepts such as federated searches.