⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
Data Architecture • Room 2

Index Architecture & Data Tiering

Index design has massive downstream consequences for performance, cost, and compliance. The architect must balance: granularity (one index per sourcetype vs. consolidated indexes), retention (hot/warm/cold/frozen tiers), and access control (role-based index permissions).

SmartStore extends Splunk into object storage (S3, GCS) for the cold tier, dramatically reducing infrastructure costs for large retention requirements. The architect configures the cache manager to balance local SSD (hot/warm) against object storage (cold), ensuring search latency SLAs are met.

Data Model Acceleration (DMA) is a pre-aggregation layer. The architect enables DMA on CIM-compliant data models, allowing tstats to return results in seconds on months of data. The tradeoff is additional disk consumption (typically 20-40% of raw data size).

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 1
An architect needs to retain 7 years of firewall logs for compliance but minimize cost. What is the best architectural approach?
AStore all 7 years in hot/warm buckets on local SSD
BUse SmartStore with S3 as the cold tier and aggressive bucket migration policies
CDelete logs after 90 days to save space
DSummary index the data and delete raw logs after 30 days