Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SplunkのData Model Accelerationは何故早いのか
Search
odorusatoshi
September 02, 2019
Technology
1
1.2k
SplunkのData Model Accelerationは何故早いのか
Data Model Acceleration(データモデル高速化)の仕組みをご紹介。
odorusatoshi
September 02, 2019
Tweet
Share
More Decks by odorusatoshi
See All by odorusatoshi
AWS VPC Traffic Mirroringを使って Fraud監視をスタート!
odorusatoshi
0
220
無償のセキュリティ神Apps10選
odorusatoshi
0
710
SplunkとThreat Hunting
odorusatoshi
1
1.3k
Splunking_webproxy
odorusatoshi
0
390
Splunking_ActiveDirectory
odorusatoshi
0
350
Splunking_fw_dns
odorusatoshi
0
540
Splunking_sysmon
odorusatoshi
0
460
Splunking_AWS_security
odorusatoshi
0
290
Other Decks in Technology
See All in Technology
【LT】ソフトウェア産業は進化しているのか? #Agilejapan
takabow
0
120
SDNという名のデータプレーンプログラミングの歴史
ebiken
PRO
2
220
クラウドインフラ構築における.NETとその他IaCの比較
ymd65536
1
110
個人でもIAM Identity Centerを使おう!(アクセス管理編)
ryder472
4
250
アプリエンジニアのためのGraphQL入門.pdf
spycwolf
0
140
初心者向けAWS Securityの勉強会mini Security-JAWSを9ヶ月ぐらい実施してきての近況
cmusudakeisuke
0
150
アジャイルチームがらしさを発揮するための目標づくり / Making the goal and enabling the team
kakehashi
4
360
CDCL による厳密解法を採用した MILP ソルバー
imai448
3
360
共創するアーキテクチャ ~チーム全体で築く持続可能な開発エコシステム~ / Co-Creating Architecture - A Sustainable Development Ecosystem Built by the Entire Team
bitkey
PRO
0
860
組織成長を加速させるオンボーディングの取り組み
sudoakiy
3
340
AWS Lambda のトラブルシュートをしていて思うこと
kazzpapa3
2
210
静的解析で実現した効率的なi18n対応の仕組みづくり
minako__ph
2
1.6k
Featured
See All Featured
Dealing with People You Can't Stand - Big Design 2015
cassininazir
365
24k
5 minutes of I Can Smell Your CMS
philhawksworth
202
19k
The Straight Up "How To Draw Better" Workshop
denniskardys
232
140k
Embracing the Ebb and Flow
colly
84
4.5k
Put a Button on it: Removing Barriers to Going Fast.
kastner
59
3.5k
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
42
9.2k
Principles of Awesome APIs and How to Build Them.
keavy
126
17k
Testing 201, or: Great Expectations
jmmastey
38
7.1k
Easily Structure & Communicate Ideas using Wireframe
afnizarnur
191
16k
For a Future-Friendly Web
brad_frost
175
9.4k
Performance Is Good for Brains [We Love Speed 2024]
tammyeverts
6
450
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
26
2.1k
Transcript
© 2018 SPLUNK INC. © 2018 SPLUNK INC. Data Model
Acceleration Senior Sales Engineer 2019.07.06 Ver0.2
© 2018 SPLUNK INC. .C
@A024 # "$6 !E3 # # "$/; =Authentication# *#+ # "$172 &+%-D 9B)8 &+% ?: (,$# "$/;5<4 ># "$Authentication'"$
© 2018 SPLUNK INC. Pivot# " $ (=)
!
© 2018 SPLUNK INC. ▶ ,4) • +4)4('#:6A<(&.(2@ -1(.tsidx*2)EC •
-1indexbucket=?N • -17;UQ> -1TRM J -1307;UPO • (&.(2$03!/4D@85 -1@#)3"LKG?(& .(29C@1%#FSHB ▶ I • _raw .tsidx ”” .'+*,.)- !&.#+(.!.$
© 2018 SPLUNK INC. :8'+(.tsidx%,)/= #!(#, *-).10 .tsidx2&.!64?> rawdata
5 < 3;"10 .tsidx2$-97 RawData
© 2018 SPLUNK INC. #! "#!
*%($# +) ($ . "'&0/ • 100% 21($ # +) • 46.12MB- , !
© 2018 SPLUNK INC. VS " 5/ #$-6
0Authentication2 0Authentication!1' +%)$ ,* )$2 (&43 19.202. 4.633.
© 2018 SPLUNK INC. * ' @=+
E/BC46'(Linuxwindows vpn )< %&+46?> &#<1 CIM;D Datamodel9, | datamodel *A+ !(3/246' Datamodel8 ) $ Datamodel *A+ %( :@+ *A(tstats) 8 )F | tstats !(3/246' Datamodel8 SPL !) $ Datamodel *A+ %( :@+ Pivot-78 & #5. | pivot "-7 0 ,$( '# "( ( ) I M f e f e fd C M d
© 2018 SPLUNK INC. |datamodel
|datamodel Authentication search | search
© 2018 SPLUNK INC. |tstats Datamodel
|tstats summariesonly=true count from datamodel=Authentication groupby Authentication.user
© 2018 SPLUNK INC. stats VS tstats VS tstats(summariesonly=t) Firewall
! • 0.299 • tstats summariesonly=t • ! $ • 4.239 • tstats summariesonly=f • #"_raw • 28.966 • stats
© 2018 SPLUNK INC. ▶ #& $"%!& * https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Aboutsummaryindex
ing ▶ PIVOT vs DATAMODEL vs TSTATS (by Splunk Answers) https://answers.splunk.com/answers/330264/pivot-vs-datamodel-vs-tstats.html ▶ ' How Search Works - $$TSIDXTERM + () https://www.slideshare.net/takashikomatsubara50/how-search-works-tsidxterm