Mar 10, 2021, 12:00 – 3:00 AM
Do you have dashboards that load too slowly to comfortably use, especially with wide timepicker windows? Do you understand how the Splunk dashboard architecture works? Have you performed a tradeoff analysis on cache vs. lookups vs. data models vs. data model acceleration? Come and hear a "pain-by-numbers" use-case about the evolution of a complex dashboard that processes very large datasets.
Train-Wreck to Bullet-Train: Dashboard Evolution for very large datasets
Do you have dashboards that load too slowly to comfortably use, especially with wide timepicker windows? Do you understand how the Splunk dashboard architecture works? Have you performed a tradeoff analysis on cache vs. lookups vs. data models vs. data model acceleration? Come and hear a "pain-by-numbers" use-case about the evolution of a complex dashboard that processes very large datasets. Yes, this is related to the previous DASUG event/project.
Topics
* General requirements and architecture
* Base/Post-process Searches and Data Cubes
* The Rumsfeld Doctrine: Unknowns going into the design (future-casting)
* Initial dashboard (cache-based)
* Performance Problems
* Tradeoff Analysis
* Data Model Acceleration (DMA)
* Performance Improvements
* Dashboard Tradeoffs / Lessons Learned
Splunxter, Inc.
Sr Consultant
Wednesday, March 10, 2021
12:00 AM – 3:00 AM UTC
Soft Start |
Hard Start |
Q & A |
Free Time |
Contact Us