In this chapter, we introduced and provided a definition of Splunk's data models, pivots (along with pivot elements and filters) as well as sparklines. By going through the given simple examples, the reader has hopefully grasped the power of these features.
Although Splunk has always performed well, version 7.0 added optimizations to its core modules, which has led to speed up improvement to 20 times against accelerated log data (tstats), and speed up improvement to 200 times against non-accelerated log or event data when querying metrics. There is also considerably less usage of resources with real-time metrics queries. Although these improvements may depend upon specific environments, you should expect to see a visible improvement in your use.
In the next chapter, we will cover simple XML dashboards; their purpose; using wizards to build, schedule the generation of, and edit XML directly; and building forms.