Lock in $30 Savings on PRO—Offer Ends Soon! ⏳
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SplunkのData Model Accelerationは何故早いのか
Search
odorusatoshi
September 02, 2019
Technology
1
1.5k
SplunkのData Model Accelerationは何故早いのか
Data Model Acceleration(データモデル高速化)の仕組みをご紹介。
odorusatoshi
September 02, 2019
Tweet
Share
More Decks by odorusatoshi
See All by odorusatoshi
入門 PEAK Threat Hunting @SECCON
odorusatoshi
0
380
AWS VPC Traffic Mirroringを使って Fraud監視をスタート!
odorusatoshi
0
280
無償のセキュリティ神Apps10選
odorusatoshi
0
1k
SplunkとThreat Hunting
odorusatoshi
1
1.5k
Splunking_webproxy
odorusatoshi
0
440
Splunking_ActiveDirectory
odorusatoshi
0
390
Splunking_fw_dns
odorusatoshi
0
580
Splunking_sysmon
odorusatoshi
0
520
Splunking_AWS_security
odorusatoshi
0
330
Other Decks in Technology
See All in Technology
私のRails開発環境
yahonda
0
170
一億総業務改善を支える社内AIエージェント基盤の要諦
yukukotani
9
2.7k
インフラ室事例集
mixi_engineers
PRO
2
190
IPv6-mostly field report from RubyKaigi 2026
sorah
0
250
【保存版】「ガチャ」からの脱却:Gemini × Veoで作る、意図を反映するAI動画制作ワークフロー
nekoailab
0
130
Capture Checking / Separation Checking 入門
tanishiking
0
110
Bakuraku Engineering Team Deck
layerx
PRO
10
3k
Introduction to Sansan for Engineers / エンジニア向け会社紹介
sansan33
PRO
5
46k
MS Ignite 2025で発表されたFoundry IQをRecap
satodayo
3
220
AI 時代のデータ戦略
na0
8
3.1k
事業部のプロジェクト進行と開発チームの改善の “時間軸" のすり合わせ
konifar
9
2.5k
Kill the Vibe?Architecture in the age of AI
stoth
1
160
Featured
See All Featured
No one is an island. Learnings from fostering a developers community.
thoeni
21
3.5k
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
46
7.8k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.7k
Build The Right Thing And Hit Your Dates
maggiecrowley
38
3k
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.5k
Understanding Cognitive Biases in Performance Measurement
bluesmoon
31
2.7k
Git: the NoSQL Database
bkeepers
PRO
432
66k
Product Roadmaps are Hard
iamctodd
PRO
55
12k
Scaling GitHub
holman
464
140k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
21
1.3k
A designer walks into a library…
pauljervisheath
210
24k
Site-Speed That Sticks
csswizardry
13
980
Transcript
© 2018 SPLUNK INC. © 2018 SPLUNK INC. Data Model
Acceleration Senior Sales Engineer 2019.07.06 Ver0.2
© 2018 SPLUNK INC. .C
@A024 # "$6 !E3 # # "$/; =Authentication# *#+ # "$172 &+%-D 9B)8 &+% ?: (,$# "$/;5<4 ># "$Authentication'"$
© 2018 SPLUNK INC. Pivot# " $ (=)
!
© 2018 SPLUNK INC. ▶ ,4) • +4)4('#:6A<(&.(2@ -1(.tsidx*2)EC •
-1indexbucket=?N • -17;UQ> -1TRM J -1307;UPO • (&.(2$03!/4D@85 -1@#)3"LKG?(& .(29C@1%#FSHB ▶ I • _raw .tsidx ”” .'+*,.)- !&.#+(.!.$
© 2018 SPLUNK INC. :8'+(.tsidx%,)/= #!(#, *-).10 .tsidx2&.!64?> rawdata
5 < 3;"10 .tsidx2$-97 RawData
© 2018 SPLUNK INC. #! "#!
*%($# +) ($ . "'&0/ • 100% 21($ # +) • 46.12MB- , !
© 2018 SPLUNK INC. VS " 5/ #$-6
0Authentication2 0Authentication!1' +%)$ ,* )$2 (&43 19.202. 4.633.
© 2018 SPLUNK INC. * ' @=+
E/BC46'(Linuxwindows vpn )< %&+46?> &#<1 CIM;D Datamodel9, | datamodel *A+ !(3/246' Datamodel8 ) $ Datamodel *A+ %( :@+ *A(tstats) 8 )F | tstats !(3/246' Datamodel8 SPL !) $ Datamodel *A+ %( :@+ Pivot-78 & #5. | pivot "-7 0 ,$( '# "( ( ) I M f e f e fd C M d
© 2018 SPLUNK INC. |datamodel
|datamodel Authentication search | search
© 2018 SPLUNK INC. |tstats Datamodel
|tstats summariesonly=true count from datamodel=Authentication groupby Authentication.user
© 2018 SPLUNK INC. stats VS tstats VS tstats(summariesonly=t) Firewall
! • 0.299 • tstats summariesonly=t • ! $ • 4.239 • tstats summariesonly=f • #"_raw • 28.966 • stats
© 2018 SPLUNK INC. ▶ #& $"%!& * https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Aboutsummaryindex
ing ▶ PIVOT vs DATAMODEL vs TSTATS (by Splunk Answers) https://answers.splunk.com/answers/330264/pivot-vs-datamodel-vs-tstats.html ▶ ' How Search Works - $$TSIDXTERM + () https://www.slideshare.net/takashikomatsubara50/how-search-works-tsidxterm