Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SplunkのData Model Accelerationは何故早いのか
Search
odorusatoshi
September 02, 2019
Technology
1.6k
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
SplunkのData Model Accelerationは何故早いのか
Data Model Acceleration(データモデル高速化)の仕組みをご紹介。
odorusatoshi
September 02, 2019
More Decks by odorusatoshi
See All by odorusatoshi
入門 PEAK Threat Hunting @SECCON
odorusatoshi
0
500
AWS VPC Traffic Mirroringを使って Fraud監視をスタート!
odorusatoshi
0
310
無償のセキュリティ神Apps10選
odorusatoshi
0
1.3k
SplunkとThreat Hunting
odorusatoshi
1
1.6k
Splunking_webproxy
odorusatoshi
0
460
Splunking_ActiveDirectory
odorusatoshi
0
420
Splunking_fw_dns
odorusatoshi
0
600
Splunking_sysmon
odorusatoshi
0
550
Splunking_AWS_security
odorusatoshi
0
340
Other Decks in Technology
See All in Technology
Databricks における 生成AIガバナンスの実践
taka_aki
1
320
運用を見据えたAIエージェント設計実践
amacbee
1
2.9k
ITエンジニアを取り巻く環境とキャリアパス / A career path for Japanese IT engineers
takatama
4
1.8k
TypeScript Compiler APIとPHP-Parserを活用し、TypeScriptとPHPで型を共有する
shuta13
0
360
個人の発見を、組織の知恵に 〜生成AI活用を"探索"から"組織の仕組み"へ〜
kintotechdev
2
990
EventBridge Connection
_kensh
4
560
AIガバナンス実践 - 生成AIコネクタのデータ漏洩リスクと実務対策
knishioka
0
190
Terraformモジュールは、なぜ「魔境」化するのか
hayama17
1
190
美味しいスイスチーズを作ろう🧀🐭
taigamikami
1
240
ルールやカスタム機能、どう使う?理想の出力を引き出すために今知りたいIBM Bob 5つの機能
muehara
1
340
SIer20年! 培ったスキルがスタートアップで輝く時
shucho0103
0
420
価格.comをAI駆動で全面刷新する ー 30年分の技術的負債を返し、次の30年の土台をつくる ー / AI Engineering Summit Tokyo 2026
tkyowa
49
53k
Featured
See All Featured
Being A Developer After 40
akosma
91
590k
Prompt Engineering for Job Search
mfonobong
0
330
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
11
940
Designing for Timeless Needs
cassininazir
1
250
Introduction to Domain-Driven Design and Collaborative software design
baasie
1
820
技術選定の審美眼(2025年版) / Understanding the Spiral of Technologies 2025 edition
twada
PRO
118
120k
Why Your Marketing Sucks and What You Can Do About It - Sophie Logan
marketingsoph
0
160
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.8k
Highjacked: Video Game Concept Design
rkendrick25
PRO
1
380
Winning Ecommerce Organic Search in an AI Era - #searchnstuff2025
aleyda
1
2k
Raft: Consensus for Rubyists
vanstee
141
7.5k
Paper Plane
katiecoart
PRO
1
51k
Transcript
© 2018 SPLUNK INC. © 2018 SPLUNK INC. Data Model
Acceleration Senior Sales Engineer 2019.07.06 Ver0.2
© 2018 SPLUNK INC. .C
@A024 # "$6 !E3 # # "$/; =Authentication# *#+ # "$172 &+%-D 9B)8 &+% ?: (,$# "$/;5<4 ># "$Authentication'"$
© 2018 SPLUNK INC. Pivot# " $ (=)
!
© 2018 SPLUNK INC. ▶ ,4) • +4)4('#:6A<(&.(2@ -1(.tsidx*2)EC •
-1indexbucket=?N • -17;UQ> -1TRM J -1307;UPO • (&.(2$03!/4D@85 -1@#)3"LKG?(& .(29C@1%#FSHB ▶ I • _raw .tsidx ”” .'+*,.)- !&.#+(.!.$
© 2018 SPLUNK INC. :8'+(.tsidx%,)/= #!(#, *-).10 .tsidx2&.!64?> rawdata
5 < 3;"10 .tsidx2$-97 RawData
© 2018 SPLUNK INC. #! "#!
*%($# +) ($ . "'&0/ • 100% 21($ # +) • 46.12MB- , !
© 2018 SPLUNK INC. VS " 5/ #$-6
0Authentication2 0Authentication!1' +%)$ ,* )$2 (&43 19.202. 4.633.
© 2018 SPLUNK INC. * ' @=+
E/BC46'(Linuxwindows vpn )< %&+46?> &#<1 CIM;D Datamodel9, | datamodel *A+ !(3/246' Datamodel8 ) $ Datamodel *A+ %( :@+ *A(tstats) 8 )F | tstats !(3/246' Datamodel8 SPL !) $ Datamodel *A+ %( :@+ Pivot-78 & #5. | pivot "-7 0 ,$( '# "( ( ) I M f e f e fd C M d
© 2018 SPLUNK INC. |datamodel
|datamodel Authentication search | search
© 2018 SPLUNK INC. |tstats Datamodel
|tstats summariesonly=true count from datamodel=Authentication groupby Authentication.user
© 2018 SPLUNK INC. stats VS tstats VS tstats(summariesonly=t) Firewall
! • 0.299 • tstats summariesonly=t • ! $ • 4.239 • tstats summariesonly=f • #"_raw • 28.966 • stats
© 2018 SPLUNK INC. ▶ #& $"%!& * https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Aboutsummaryindex
ing ▶ PIVOT vs DATAMODEL vs TSTATS (by Splunk Answers) https://answers.splunk.com/answers/330264/pivot-vs-datamodel-vs-tstats.html ▶ ' How Search Works - $$TSIDXTERM + () https://www.slideshare.net/takashikomatsubara50/how-search-works-tsidxterm