Analyze Metric and Event Data on the Same Platform

Analyze both metric and event data on the same platform regardless of source or structure. With Splunk metric indexes, you can quickly and easily ingest, store, and analyze metrics — whether in the Analytics Workspace or with SPL — so you can deliver positive business results. Get the most value out of your data with Splunk.

Why Bring Metrics into Splunk?

While Splunk is the industry leader for storing and retrieving log data, did you know that you now also can store and search metrics data in Splunk as well?

A log is an event that happened and a metric is a measurement of the health of a system. Splunk now offers metric indexes. The introduction of metric indexes in addition to traditional indexes allows users to efficiently store and search both events and metrics data in Splunk. Keeping your metrics data in the Splunk metric indexes uses less storage space than events, and increases query search speed 500 times, using less system resources at a lower licensing cost.

How to Create a Metric Index

Creating a metric index is as easy as toggling the data type while you create your new index. There are multiple ways to bring metrics into your new metrics index — you can bring data in directly as metrics or convert your already ingested event data into metrics for faster analysis in Splunk:

Query Your Metrics Easily

Once your data is in a Metric Index, Splunk has a powerful UI tool that allows you to search it without any SPL — the Analytics Workspace.

Use the Analytics Workspace to quickly browse and visualize your metrics data with different types of charts. Apply filters, dimension splits, and aggregations to gain insights into your data. Create reports, alerts, and dashboard panels without using SPL. The Splunk Analytics Workspace helps you to quickly identify and respond to any issues or anomalies in your data.

If you prefer to search your data using SPL, you can access and analyze your data with the Search and Reporting app using metrics-specific commands like mstats and mcatalog.

Alert on Your Metrics

Once you start tracking your metrics, you can monitor them and set up a Splunk alert to find out you are in or out of your target range.

Whether you use the Analytics Workspace or SPL to analyze your metrics data, you can easily create a new type of streaming metric alert to stay informed on your health. Streaming alerts are more efficient than traditional scheduled alerts and can scale up to tens of thousands of alerts.

Keep Your Metrics Handy for Future Reference

After a year of tracking your metric regularly, you may want to zoom out and see your monthly or yearly average and store your summaries for future reference. This is where metric rollups become useful. Splunk lets you define metric roll ups that summarize your metric data into indexes that are optimized for long-term storage and review.

You can create different time frame based rollups of your data and take advantage of faster query time using these rolled-up indexes.

So What?

Splunk’s underlying technology powers the ability to analyze both metrics and event data in the same platform. No matter your data source or structure, you can get the most value from your data, and invest in only one tool to do it — with Splunk. Try a free trial of Splunk Enterprise or Splunk Cloud to see for yourself.

To learn more about self service analytics capabilities at Splunk and see a hands-on demo of the Analytics Workspace discussed in this blog, join us for the Splunk Self Service Analytics Tech Talk Webinar.

Related Articles

Smarter Root Cause Analysis: Determining Causality from your ITSI KPIs
Platform
2 Minute Read

Smarter Root Cause Analysis: Determining Causality from your ITSI KPIs

Root cause analysis can be a difficult challenge when you are troubleshooting complex IT systems. In this blog, we are going to take you through how you can perform root cause analysis on your IT Service Intelligence (ITSI) episodes using machine learning, or more specifically causal inference.
Smarter ITSI Episodes Powered by Community Detection Algorithms
Platform
6 Minute Read

Smarter ITSI Episodes Powered by Community Detection Algorithms

In this blog we are going to describe how you can create a notable event policy in IT Service Intelligence (ITSI) that is able to group your events using labels generated by unsupervised machine learning in the Smart ITSI Insights App for Splunk – and don’t worry you don’t have to be a data scientist to read this blog!
Making Smarter Predictions in ITSI
Platform
3 Minute Read

Making Smarter Predictions in ITSI

As we are trying to commoditize machine learning through our MLTK smart workflows, this article outlines another example of an MLTK smart workflow, designed to help improve the usability of the predictive capabilities in ITSI.
Detecting Credit Card Fraud Using SMLE
Platform
4 Minute Read

Detecting Credit Card Fraud Using SMLE

In this blog post, we’ll explore an ML-powered solution using the Splunk Machine Learning Environment to detect fraudulent credit card transactions in real time. Using out-of-the-box Splunk capabilities, we’ll walk you through how to ingest and transform log data, train a predictive model using open source algorithms, and predict fraud in real-time against transaction events.
Splunk AR: Admin AR Web App
Platform
2 Minute Read

Splunk AR: Admin AR Web App

Check out how the Splunk AR web app allows administrators to manage their entire AR experience at scale and all in one unified place.
Get to Know Splunk Machine Learning Environment (SMLE)
Platform
5 Minute Read

Get to Know Splunk Machine Learning Environment (SMLE)

An introduction to SMLE Labs and a showcase of the various ML capabilities at a high level by walking you through the environment, step-by-step.
Walkthrough to Set Up the Deep Learning Toolkit for Splunk with Amazon EKS
Platform
6 Minute Read

Walkthrough to Set Up the Deep Learning Toolkit for Splunk with Amazon EKS

Splunk DLTK supports Docker as well as Kubernetes and OpenShift as container environments. In this article, we will go through the setup for using DLTK 3.3 and Amazon EKS as a kubernetes environment.
Advanced Painting with Data: Choropleth SVG
Platform
5 Minute Read

Advanced Painting with Data: Choropleth SVG

Curious about some more advanced use cases with Choropleth SVG in Splunk? Take a look at this blog to find out about animations, custom gauges, and why emojis matter!
Splunk Cloud Self-Service: Announcing The New Admin Config Service API
Platform
3 Minute Read

Splunk Cloud Self-Service: Announcing The New Admin Config Service API

The Admin Config Service is a set of modern REST APIs that will empower Splunk Cloud admins with a simple, yet powerful set of self-service capabilities.