Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SplunkのData Model Accelerationは何故早いのか
Search
odorusatoshi
September 02, 2019
Technology
1
1.6k
SplunkのData Model Accelerationは何故早いのか
Data Model Acceleration(データモデル高速化)の仕組みをご紹介。
odorusatoshi
September 02, 2019
Tweet
Share
More Decks by odorusatoshi
See All by odorusatoshi
入門 PEAK Threat Hunting @SECCON
odorusatoshi
0
440
AWS VPC Traffic Mirroringを使って Fraud監視をスタート!
odorusatoshi
0
300
無償のセキュリティ神Apps10選
odorusatoshi
0
1.2k
SplunkとThreat Hunting
odorusatoshi
1
1.6k
Splunking_webproxy
odorusatoshi
0
450
Splunking_ActiveDirectory
odorusatoshi
0
400
Splunking_fw_dns
odorusatoshi
0
590
Splunking_sysmon
odorusatoshi
0
530
Splunking_AWS_security
odorusatoshi
0
330
Other Decks in Technology
See All in Technology
会社紹介資料 / Sansan Company Profile
sansan33
PRO
15
400k
ランサムウェア対策としてのpnpm導入のススメ
ishikawa_satoru
0
220
マネージャー視点で考えるプロダクトエンジニアの評価 / Evaluating Product Engineers from a Manager's Perspective
hiro_torii
0
170
2026年、サーバーレスの現在地 -「制約と戦う技術」から「当たり前の実行基盤」へ- /serverless2026
slsops
2
260
Bill One急成長の舞台裏 開発組織が直面した失敗と教訓
sansantech
PRO
2
400
ファインディの横断SREがTakumi byGMOと取り組む、セキュリティと開発スピードの両立
rvirus0817
1
1.6k
usermode linux without MMU - fosdem2026 kernel devroom
thehajime
0
240
AIが実装する時代、人間は仕様と検証を設計する
gotalab555
1
100
茨城の思い出を振り返る ~CDKのセキュリティを添えて~ / 20260201 Mitsutoshi Matsuo
shift_evolve
PRO
1
380
ブロックテーマでサイトをリニューアルした話 / 2026-01-31 Kansai WordPress Meetup
torounit
0
480
ECS障害を例に学ぶ、インシデント対応に備えたAIエージェントの育て方 / How to develop AI agents for incident response with ECS outage
iselegant
2
250
マーケットプレイス版Oracle WebCenter Content For OCI
oracle4engineer
PRO
5
1.6k
Featured
See All Featured
A Tale of Four Properties
chriscoyier
162
24k
What does AI have to do with Human Rights?
axbom
PRO
0
2k
Ethics towards AI in product and experience design
skipperchong
2
200
The Illustrated Guide to Node.js - THAT Conference 2024
reverentgeek
0
260
The SEO Collaboration Effect
kristinabergwall1
0
350
The innovator’s Mindset - Leading Through an Era of Exponential Change - McGill University 2025
jdejongh
PRO
1
93
Thoughts on Productivity
jonyablonski
74
5k
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
659
61k
KATA
mclloyd
PRO
34
15k
WENDY [Excerpt]
tessaabrams
9
36k
Product Roadmaps are Hard
iamctodd
PRO
55
12k
The Art of Programming - Codeland 2020
erikaheidi
57
14k
Transcript
© 2018 SPLUNK INC. © 2018 SPLUNK INC. Data Model
Acceleration Senior Sales Engineer 2019.07.06 Ver0.2
© 2018 SPLUNK INC. .C
@A024 # "$6 !E3 # # "$/; =Authentication# *#+ # "$172 &+%-D 9B)8 &+% ?: (,$# "$/;5<4 ># "$Authentication'"$
© 2018 SPLUNK INC. Pivot# " $ (=)
!
© 2018 SPLUNK INC. ▶ ,4) • +4)4('#:6A<(&.(2@ -1(.tsidx*2)EC •
-1indexbucket=?N • -17;UQ> -1TRM J -1307;UPO • (&.(2$03!/4D@85 -1@#)3"LKG?(& .(29C@1%#FSHB ▶ I • _raw .tsidx ”” .'+*,.)- !&.#+(.!.$
© 2018 SPLUNK INC. :8'+(.tsidx%,)/= #!(#, *-).10 .tsidx2&.!64?> rawdata
5 < 3;"10 .tsidx2$-97 RawData
© 2018 SPLUNK INC. #! "#!
*%($# +) ($ . "'&0/ • 100% 21($ # +) • 46.12MB- , !
© 2018 SPLUNK INC. VS " 5/ #$-6
0Authentication2 0Authentication!1' +%)$ ,* )$2 (&43 19.202. 4.633.
© 2018 SPLUNK INC. * ' @=+
E/BC46'(Linuxwindows vpn )< %&+46?> &#<1 CIM;D Datamodel9, | datamodel *A+ !(3/246' Datamodel8 ) $ Datamodel *A+ %( :@+ *A(tstats) 8 )F | tstats !(3/246' Datamodel8 SPL !) $ Datamodel *A+ %( :@+ Pivot-78 & #5. | pivot "-7 0 ,$( '# "( ( ) I M f e f e fd C M d
© 2018 SPLUNK INC. |datamodel
|datamodel Authentication search | search
© 2018 SPLUNK INC. |tstats Datamodel
|tstats summariesonly=true count from datamodel=Authentication groupby Authentication.user
© 2018 SPLUNK INC. stats VS tstats VS tstats(summariesonly=t) Firewall
! • 0.299 • tstats summariesonly=t • ! $ • 4.239 • tstats summariesonly=f • #"_raw • 28.966 • stats
© 2018 SPLUNK INC. ▶ #& $"%!& * https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Aboutsummaryindex
ing ▶ PIVOT vs DATAMODEL vs TSTATS (by Splunk Answers) https://answers.splunk.com/answers/330264/pivot-vs-datamodel-vs-tstats.html ▶ ' How Search Works - $$TSIDXTERM + () https://www.slideshare.net/takashikomatsubara50/how-search-works-tsidxterm