Index design has massive downstream consequences for performance, cost, and compliance. The architect must balance: granularity (one index per sourcetype vs. consolidated indexes), retention (hot/warm/cold/frozen tiers), and access control (role-based index permissions).
SmartStore extends Splunk into object storage (S3, GCS) for the cold tier, dramatically reducing infrastructure costs for large retention requirements. The architect configures the cache manager to balance local SSD (hot/warm) against object storage (cold), ensuring search latency SLAs are met.
Data Model Acceleration (DMA) is a pre-aggregation layer. The architect enables DMA on CIM-compliant data models, allowing tstats to return results in seconds on months of data. The tradeoff is additional disk consumption (typically 20-40% of raw data size).