Data Model Advantages - ironstream_for_splunk - ironstream_for_elastic - ironstream_for_kafka - 1.0

Ironstream for Splunk®/Kafka®/Elastic® Ironstream Data Model for IBM i Readme

Product type
Software
Portfolio
Integrate
Product family
Ironstream™ software
Product
Ironstream™ software > Ironstream™ software for Splunk®
Ironstream™ software > Ironstream™ software for Elastic®
Ironstream™ software > Ironstream™ software for Kafka®
Version
1.0
ft:locale
en-US
Product name
Ironstream Splunk®/Kafka®/Elastic®
ft:title
Ironstream for Splunk®/Kafka®/Elastic® Ironstream Data Model for IBM i Readme
Copyright
2020
First publish date
2014
ft:lastEdition
2023-08-25
ft:lastPublication
2023-08-28T08:30:26.212000

According to the Splunk documentation, a data model is a “Hierarchically structured search-time mapping of semantic knowledge about one or more datasets. It encodes the domain knowledge necessary to build a variety of specialized searches of those datasets.”

Using a data model enables some distinct advantages over “raw” Splunk indexed data. The following list gives examples of ways in which the Ironstream Data Model for IBM i can realize these advantages:

  • Data is structured into logical, hierarchical groups with field inheritance.

  • Field names can be presented as more readily recognizable terms. For example, the IBM i Collection Services field PONBR can become Pool Number.

  • Calculations are defined as part of the data model for reuse by any Splunk user. For example, Splunk users do not need to understand how to calculate the CPU utilization of an LPAR.

  • The Splunk Pivot tool can be used to build reports and dashboards.

  • Splunk commands like tstats and datamodel can be used for enhanced searching.

  • There is no impact on your Splunk license.