<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Common Information Model (CIM) Performance Tuning in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Common-Information-Model-CIM-Performance-Tuning/m-p/597401#M76803</link>
    <description>&lt;P&gt;Hello.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Our organization has one of our Data Model (DM) searches for ES regularly running over 200 seconds to complete.&amp;nbsp; Soon another source will be added to the DM, so I have been looking for ways to reduce the runtime.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I came across a site that suggested the macros that build the CIM DM's could be faster by adding the sourcetype alongside the index in the search.&amp;nbsp; My thought was, "Why stop there?"&amp;nbsp; You could add the source too, as long as it doesn't iterate with a date or some random number scheme.&amp;nbsp; And even then, with reasonable wildcarding at the end I believe there would be a performance improvement.&lt;BR /&gt;&lt;BR /&gt;I was told that this effort is unnecessary, even though in my unofficial tests over the same period, I found my modified searches to nearly twice as fast.&amp;nbsp; So aside from the additional effort to build those searches and maintain them, why is this unnecessary?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;AJ&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2022 13:42:04 GMT</pubDate>
    <dc:creator>kernand0</dc:creator>
    <dc:date>2022-05-11T13:42:04Z</dc:date>
    <item>
      <title>Common Information Model (CIM) Performance Tuning</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Common-Information-Model-CIM-Performance-Tuning/m-p/597401#M76803</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Our organization has one of our Data Model (DM) searches for ES regularly running over 200 seconds to complete.&amp;nbsp; Soon another source will be added to the DM, so I have been looking for ways to reduce the runtime.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I came across a site that suggested the macros that build the CIM DM's could be faster by adding the sourcetype alongside the index in the search.&amp;nbsp; My thought was, "Why stop there?"&amp;nbsp; You could add the source too, as long as it doesn't iterate with a date or some random number scheme.&amp;nbsp; And even then, with reasonable wildcarding at the end I believe there would be a performance improvement.&lt;BR /&gt;&lt;BR /&gt;I was told that this effort is unnecessary, even though in my unofficial tests over the same period, I found my modified searches to nearly twice as fast.&amp;nbsp; So aside from the additional effort to build those searches and maintain them, why is this unnecessary?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;AJ&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 13:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Common-Information-Model-CIM-Performance-Tuning/m-p/597401#M76803</guid>
      <dc:creator>kernand0</dc:creator>
      <dc:date>2022-05-11T13:42:04Z</dc:date>
    </item>
  </channel>
</rss>

