Analyze Metric and Event Data on the Same Platform

Analyze both metric and event data on the same platform regardless of source or structure. With Splunk metric indexes, you can quickly and easily ingest, store, and analyze metrics — whether in the Analytics Workspace or with SPL — so you can deliver positive business results. Get the most value out of your data with Splunk.

Why Bring Metrics into Splunk?

While Splunk is the industry leader for storing and retrieving log data, did you know that you now also can store and search metrics data in Splunk as well?

A log is an event that happened and a metric is a measurement of the health of a system. Splunk now offers metric indexes. The introduction of metric indexes in addition to traditional indexes allows users to efficiently store and search both events and metrics data in Splunk. Keeping your metrics data in the Splunk metric indexes uses less storage space than events, and increases query search speed 500 times, using less system resources at a lower licensing cost.

How to Create a Metric Index

Creating a metric index is as easy as toggling the data type while you create your new index. There are multiple ways to bring metrics into your new metrics index — you can bring data in directly as metrics or convert your already ingested event data into metrics for faster analysis in Splunk:

Query Your Metrics Easily

Once your data is in a Metric Index, Splunk has a powerful UI tool that allows you to search it without any SPL — the Analytics Workspace.

Use the Analytics Workspace to quickly browse and visualize your metrics data with different types of charts. Apply filters, dimension splits, and aggregations to gain insights into your data. Create reports, alerts, and dashboard panels without using SPL. The Splunk Analytics Workspace helps you to quickly identify and respond to any issues or anomalies in your data.

If you prefer to search your data using SPL, you can access and analyze your data with the Search and Reporting app using metrics-specific commands like mstats and mcatalog.

Alert on Your Metrics

Once you start tracking your metrics, you can monitor them and set up a Splunk alert to find out you are in or out of your target range.

Whether you use the Analytics Workspace or SPL to analyze your metrics data, you can easily create a new type of streaming metric alert to stay informed on your health. Streaming alerts are more efficient than traditional scheduled alerts and can scale up to tens of thousands of alerts.

Keep Your Metrics Handy for Future Reference

After a year of tracking your metric regularly, you may want to zoom out and see your monthly or yearly average and store your summaries for future reference. This is where metric rollups become useful. Splunk lets you define metric roll ups that summarize your metric data into indexes that are optimized for long-term storage and review.

You can create different time frame based rollups of your data and take advantage of faster query time using these rolled-up indexes.

So What?

Splunk’s underlying technology powers the ability to analyze both metrics and event data in the same platform. No matter your data source or structure, you can get the most value from your data, and invest in only one tool to do it — with Splunk. Try a free trial of Splunk Enterprise or Splunk Cloud to see for yourself.

To learn more about self service analytics capabilities at Splunk and see a hands-on demo of the Analytics Workspace discussed in this blog, join us for the Splunk Self Service Analytics Tech Talk Webinar.

Related Articles

Developing the Splunk App for Anomaly Detection
Platform
13 Minute Read

Developing the Splunk App for Anomaly Detection

A technical overview of the Splunk App for Anomaly Detection, which uses machine learning to automatically configure anomaly detection jobs on time series data.
Enhancements To Ingest Actions Improve Usability and Expand Searchability Wherever Your Data Lives
Platform
4 Minute Read

Enhancements To Ingest Actions Improve Usability and Expand Searchability Wherever Your Data Lives

Along with the respective Splunk Enterprise version 9.1.0 and Splunk Cloud Version 9.0.2305 releases, Ingest Actions has launched a new set of features and capabilities that improve its usability and expand on configurability of data routed by Ingest Actions to S3.
Flatten the SPL Learning Curve: Introducing Splunk AI Assistant for SPL
Platform
3 Minute Read

Flatten the SPL Learning Curve: Introducing Splunk AI Assistant for SPL

At .conf23, we announced the preview release of Splunk AI Assistant - Splunk's first offering powered by generative AI.
Splunk Edge Processor Enhancements Offer Greater Data Access and Improve Data Management
Platform
1 Minute Read

Splunk Edge Processor Enhancements Offer Greater Data Access and Improve Data Management

On the heels of an exciting GA in March and the April announcement of its regional expansion, we are excited to share the latest updates to Splunk Edge Processor that will make it even easier for customers to have more flexibility and control over just the data you want, nothing more nothing less.
Fastest Time-to-Value Anomaly Detection in Splunk: The Splunk App for Anomaly Detection 1.1.0
Platform
3 Minute Read

Fastest Time-to-Value Anomaly Detection in Splunk: The Splunk App for Anomaly Detection 1.1.0

Splunk App for Anomaly Detection simplifies ML, making anomaly detection easy. It streamlines tasks, enabling ML integration in everyday workflows. Just load data, select the field, and click "Detect Anomalies."
Swimming in Sensors and Drowning in Data: The Role of Splunk Partners in Delivering Splunk Edge Hub
Platform
3 Minute Read

Swimming in Sensors and Drowning in Data: The Role of Splunk Partners in Delivering Splunk Edge Hub

With the proliferation of edge computing and the release of Splunk Edge Hub, partners have additional functionality to accelerate the detection, investigation and response of threats and issues that will inevitably occur in physical and industrial environments.
Introducing New Deep Learning NLP Assistants for DSDL
Platform
6 Minute Read

Introducing New Deep Learning NLP Assistants for DSDL

The Splunk App for Data Science and Deep Learning (DSDL) now has two new assistant features for Natural Language Processing. DSDL has been offering basic natural language processing (NLP) capabilities using the spaCy library.
Announcing the General Availability of Cloud Monitoring Console’s Maintenance Dashboard
Platform
3 Minute Read

Announcing the General Availability of Cloud Monitoring Console’s Maintenance Dashboard

The new Maintenance Dashboard in the Cloud Monitoring Console app aims to assist Splunk Cloud Platform admins in effectively managing maintenance tasks and staying informed about Splunk-initiated maintenance for improved operational efficiency.
What is Splunk Virtual Compute (SVC)?
Platform
7 Minute Read

What is Splunk Virtual Compute (SVC)?

Learn about what SVCs are, how they fit in with workload pricing, and how to size, monitor, and manage workload to get the most out of Splunk.