Release Notes

 


Massively scalable search

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Massively scalable search

Not only is search about ten times faster than the previous release, but we've added several new features that empower users to search smarter and faster; a few of these features are highlighted in this Splunk developer's blog post. Read on for more information.

Analyze large data sets

This feature allows users to run reports over hundreds of millions of results and terabytes of data from within Splunk's new user interface. While previous versions of Splunk allowed users to perform searches over 50,000 results from the command line (the 'dispatch' command), this capability has been enhanced and has been now incorporated into the new user interface. As part of this integration with the new user interface, users no longer need to wait for searches to complete. They can interact with results as as search runs in real-time, add/remove fields, and page through results.

Other scaling-related enhancements include:

For information about Splunk's powerful search tools, refer to "About search"in the User Manual

New highly responsive user interface

This feature includes a completely redesigned and more intuitive core Splunk search interface. Capabilities include:

Learn more about using Splunk's redesigned core search interface.

Job management and control

This feature allows users and administrators greater flexibility in managing more concurrent searches and longer running searches.

Through Splunk's new job management user interface, users and administrators will be able to:

Additionally, search jobs now run in a separate process, allowing searches to run independently of the Splunk indexer. Individual search jobs will be accessible to the administrator directly from the user's operating system.


Learn more about managing your search jobs.

Faster complex searches

This feature includes significant back-end improvements to Splunk's search speed, especially for more complex searches. Improvements include:

Faster distributed search

This feature includes significant back-end improvements to Splunk's performance in distributed environments. Improvements include:

Learn more about using distributed search.

Benefits

For users:

For administrators:

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!