Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SplunkのData Model Accelerationは何故早いのか
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
odorusatoshi
September 02, 2019
Technology
1.6k
1
Share
SplunkのData Model Accelerationは何故早いのか
Data Model Acceleration(データモデル高速化)の仕組みをご紹介。
odorusatoshi
September 02, 2019
More Decks by odorusatoshi
See All by odorusatoshi
入門 PEAK Threat Hunting @SECCON
odorusatoshi
0
490
AWS VPC Traffic Mirroringを使って Fraud監視をスタート!
odorusatoshi
0
310
無償のセキュリティ神Apps10選
odorusatoshi
0
1.3k
SplunkとThreat Hunting
odorusatoshi
1
1.6k
Splunking_webproxy
odorusatoshi
0
460
Splunking_ActiveDirectory
odorusatoshi
0
410
Splunking_fw_dns
odorusatoshi
0
600
Splunking_sysmon
odorusatoshi
0
540
Splunking_AWS_security
odorusatoshi
0
340
Other Decks in Technology
See All in Technology
エムスリーテクノロジーズ株式会社 エンジニア向け紹介資料 / M3 Technologies Company Deck
m3_engineering
0
190
AI全盛の今だからこそ、あえてもう一度振り返るAPIの基礎
smt7174
3
130
最新技術を"今は選ばない"という技術選定
leveragestech
PRO
0
250
TypeScriptで実現する既存APIを活用したリモートMCPサーバー構築 / TSKaigi 2026
soarteclab
0
110
The Bag-of-Documents Model for Query Understanding and Retrieval
dtunkelang
0
160
AWS運用におけるAI Agent活用術 / JAWS-UG 神戸 #11 LT大会
genda
1
300
実践 TanStack Start ― 新規プロダクトを開発して確立した、サーバーとクライアント境界の設計パターン / Practical TanStack Start Server-Client Boundary Patterns
kaminashi
1
100
20260515 ログイン機能だけではないアカウント管理を全体で考える~サービス設計者向け~
oidfj
1
810
AI 時代の Platform Engineering
recruitengineers
PRO
1
230
React Compiler導入の効果と運用の工夫
kakehashi
PRO
3
280
Purview 勉強会報告 Microsoft Purview 入門しようとしてみた
masakichixo
1
450
Claude Code / Codex / Kiro に AWS 権限を 渡すとき、何を設計すべきか
k_adachi_01
6
1.8k
Featured
See All Featured
The Cost Of JavaScript in 2023
addyosmani
55
9.9k
Ethics towards AI in product and experience design
skipperchong
2
270
Avoiding the “Bad Training, Faster” Trap in the Age of AI
tmiket
0
150
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
231
23k
Put a Button on it: Removing Barriers to Going Fast.
kastner
60
4.3k
We Are The Robots
honzajavorek
0
230
Deep Space Network (abreviated)
tonyrice
0
150
So, you think you're a good person
axbom
PRO
2
2k
Building a Scalable Design System with Sketch
lauravandoore
463
34k
The untapped power of vector embeddings
frankvandijk
2
1.7k
Heart Work Chapter 1 - Part 1
lfama
PRO
7
36k
コードの90%をAIが書く世界で何が待っているのか / What awaits us in a world where 90% of the code is written by AI
rkaga
61
44k
Transcript
© 2018 SPLUNK INC. © 2018 SPLUNK INC. Data Model
Acceleration Senior Sales Engineer 2019.07.06 Ver0.2
© 2018 SPLUNK INC. .C
@A024 # "$6 !E3 # # "$/; =Authentication# *#+ # "$172 &+%-D 9B)8 &+% ?: (,$# "$/;5<4 ># "$Authentication'"$
© 2018 SPLUNK INC. Pivot# " $ (=)
!
© 2018 SPLUNK INC. ▶ ,4) • +4)4('#:6A<(&.(2@ -1(.tsidx*2)EC •
-1indexbucket=?N • -17;UQ> -1TRM J -1307;UPO • (&.(2$03!/4D@85 -1@#)3"LKG?(& .(29C@1%#FSHB ▶ I • _raw .tsidx ”” .'+*,.)- !&.#+(.!.$
© 2018 SPLUNK INC. :8'+(.tsidx%,)/= #!(#, *-).10 .tsidx2&.!64?> rawdata
5 < 3;"10 .tsidx2$-97 RawData
© 2018 SPLUNK INC. #! "#!
*%($# +) ($ . "'&0/ • 100% 21($ # +) • 46.12MB- , !
© 2018 SPLUNK INC. VS " 5/ #$-6
0Authentication2 0Authentication!1' +%)$ ,* )$2 (&43 19.202. 4.633.
© 2018 SPLUNK INC. * ' @=+
E/BC46'(Linuxwindows vpn )< %&+46?> &#<1 CIM;D Datamodel9, | datamodel *A+ !(3/246' Datamodel8 ) $ Datamodel *A+ %( :@+ *A(tstats) 8 )F | tstats !(3/246' Datamodel8 SPL !) $ Datamodel *A+ %( :@+ Pivot-78 & #5. | pivot "-7 0 ,$( '# "( ( ) I M f e f e fd C M d
© 2018 SPLUNK INC. |datamodel
|datamodel Authentication search | search
© 2018 SPLUNK INC. |tstats Datamodel
|tstats summariesonly=true count from datamodel=Authentication groupby Authentication.user
© 2018 SPLUNK INC. stats VS tstats VS tstats(summariesonly=t) Firewall
! • 0.299 • tstats summariesonly=t • ! $ • 4.239 • tstats summariesonly=f • #"_raw • 28.966 • stats
© 2018 SPLUNK INC. ▶ #& $"%!& * https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Aboutsummaryindex
ing ▶ PIVOT vs DATAMODEL vs TSTATS (by Splunk Answers) https://answers.splunk.com/answers/330264/pivot-vs-datamodel-vs-tstats.html ▶ ' How Search Works - $$TSIDXTERM + () https://www.slideshare.net/takashikomatsubara50/how-search-works-tsidxterm