17. Historical Data Storage
ColdColdCold
Cold Cold Cold Cold Cold Cold
Historical data retained online,
possibly using lower-cost storage
Hot
Warm Warm Warm
Real-time and recent data, typically
using high-speed storage
17
19. ColdColdCold
Savings Example
Hot
Warm
Driving down data retention costs
Warm
Cold Cold Cold Cold Cold Cold
Warm
Savings Over
1 Year
$1.6 M*
Savings over
5 Years
$4.3 M*
Raw Ingest: 10TB / Day
Hot/Warm Retention: 2 Months
Cold Retention: 10 Months
* Assumes $1.25/GB Cold Storage Purchase Cost, 10% Maintenance Cost, 10% Annual Data Growth, 3 Year HW Refresh, No clustering
19
23. Cloud Services Monitoring
23
New and enhanced apps to monitor critical cloud services
• URL response times
• Caching layer analysis
• Network performance
• Error log tracking
• User profiling
• Request/response perf.
Analyze the operations and
security of your AWS services
• AWS ELB
• AWS CloudFront
• New security features
• CloudTrail, Config
• CloudWatch, S3
• VPC Flow Logs, Billing
AWS
Monitor the performance,
availability, and security of
your Akamai service
Monitor ServiceNow incident,
change, and event processes
• Support for latest
“Geneva” release
Akamai
ServiceNow
26. Additional 6.4 Features
26
Feature Short Description
Ultra-drilldown and Highlighting
When performing ultra-drilldown field=value or tag filtering, the UI highlights the appropriate tags
or field=value pairs within event expansions and event details where applicable. New ultra-drilldown
actions also added for tags.
UI control for Global Default Time Range
Administrators can now define a default time range value for all search pages by using a UI control in
Splunk Web.
Instant Feedback
All formatting options in visualizations are reflected automatically in the visualizations. This gives
users much more confidence that their choices are matching their intentions.
Dashboard XML Editor
Enhanced XML edit experience that includes better screen optimization, inline validation, as well as
live preview before saving.
Indexer Cluster Enhancements Option to force roll specific hot buckets.
Ability to quarantine a bad search peer.
Search Head Cluster Enhancements User/Role/Password Replication.
Alert Logging
Ability to create a custom log event that is sent back to the Splunk platform for indexing, searching,
and reporting.
Forwarder support for Linux For Power Forwarder supported on Linux for Power on the Little Endian architecture.