When should summary indexing be used?
Using the tstats command with summariesonly=false instructs Splunk to return results from both summarized (accelerated) data and non-summarized (raw) data. This can be useful when you need a comprehensive view of the data that includes both the high-performance summaries provided by data model acceleration and the detailed granularity of raw data.
Jesusita
7 days agoMeaghan
8 days agoMichael
10 days agoCrista
12 days agoSheldon
16 days agoTora
16 days ago