Splunk Accelerated Data Models - Part 1

This article is based on my Splunk .conf 2015 session and is the first in a mini-series on Splunk data model acceleration.
Why Accelerate? Have you ever seen this?
Splunk is great and very fast with needle in a haystack searches, e.g. find a specific keyword in millions of events. It is not so fast with searches that perform calculations on millions of events, e.g. the sum or average of fields.
Logs & Metrics




















