Train-Wreck to Bullet-Train: Dashboard Evolution for very large datasets Do you have dashboards that load too slowly to comfortably use, especially with wide timepicker windows? Do you understand how the Splunk dashboard architecture works? Have you performed a tradeoff analysis on cache vs. lookups vs. data models vs. data model acceleration? Come and hear a "pain-by-numbers" use-case about the evolution of a complex dashboard that processes very large datasets. Yes, this is related to the previous DASUG event/project. Topics
* General requirements and architecture
* Base/Post-process Searches and Data Cubes
* The Rumsfeld Doctrine: Unknowns going into the design (future-casting)
* Initial dashboard (cache-based)
* Performance Problems
* Tradeoff Analysis
* Data Model Acceleration (DMA)
* Performance Improvements
* Dashboard Tradeoffs / Lessons Learned
Splunxter, Inc.
Sr Consultant
Wednesday, March 10, 2021
12:00 AM – 3:00 AM UTC
12:00 AM | Soft Start |
12:30 AM | Hard Start |
1:30 AM | Q & A |
2:00 AM | Free Time |