<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk search 'plan' in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12546#M61</link>
    <description>&lt;P&gt;This would be very cool-- like what SQL Server does with Graphical Showplan, or even (much simpler) what MySQL does with EXPLAIN.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2010 12:31:34 GMT</pubDate>
    <dc:creator>Justin_Grant</dc:creator>
    <dc:date>2010-04-29T12:31:34Z</dc:date>
    <item>
      <title>Splunk search 'plan'</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12545#M60</link>
      <description>&lt;P&gt;Is there anyway to run an sql like 'plan' on a splunk search to determine efficiency?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 07:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12545#M60</guid>
      <dc:creator>bfaber</dc:creator>
      <dc:date>2010-04-29T07:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search 'plan'</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12546#M61</link>
      <description>&lt;P&gt;This would be very cool-- like what SQL Server does with Graphical Showplan, or even (much simpler) what MySQL does with EXPLAIN.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 12:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12546#M61</guid>
      <dc:creator>Justin_Grant</dc:creator>
      <dc:date>2010-04-29T12:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search 'plan'</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12547#M62</link>
      <description>&lt;P&gt;Nope.  It's an internal discussion topic.  I'm in the sustaining group, charged with removing defects and making things more supportable.  This is one of the things we would like.  It's a bit tricky in that SQL datasets are a bit more expectable than splunk datasets, so something like a plan or explain would take more interpretation for Splunk than for SQL, but still it would be a good tool for aiding in performance analysis.&lt;/P&gt;

&lt;P&gt;Things you can do right now:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;run a search and review the search.log in var/run/dispatch/  it will have some information about expansions, so that you can see how tags, eventtypes, and so on are behaving.&lt;/LI&gt;
&lt;LI&gt;review &lt;A href="http://www.splunk.com/wiki/Community:PerformanceTroubleshooting" rel="nofollow"&gt;http://www.splunk.com/wiki/Community:PerformanceTroubleshooting&lt;/A&gt; , which down in the 'anatomy of a search' will give you a rough idea of how the machinery works, so will give you a good idea how to proceed from an expert perspective.&lt;/LI&gt;
&lt;LI&gt;work with support on specific searches you want to go faster&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If you have specific components of the information that a plan or explain would provide that are most crucial, we'd love to hear about them, and the shape of the problems you face that make these important.  Any assistance our customers can provide in scheduling decisions is very much appreciated.  I can copy things into formal enhancement requests, but ideally those kinds of things arrive via the support channel.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 14:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12547#M62</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-04-29T14:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search 'plan'</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12548#M63</link>
      <description>&lt;P&gt;I noticed in Splunk 4.1.1, there is now an &lt;EM&gt;inspect search&lt;/EM&gt; option on the &lt;EM&gt;actions&lt;/EM&gt; drop-down menu.  This isn't as detailed as a "plan", but it does give you some key information about your search along with a graph showing search times by component, as well as some component invocation counts.  It's certainly a starting point.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2010 02:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12548#M63</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-04-30T02:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search 'plan'</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12549#M64</link>
      <description>&lt;P&gt;Yep, that was our initial work on this sort of goal.  I heard about it but hadn't tried it yet.  I should perhaps edit it into my reply. I pushed for the inspect action to allow review of the search log as well.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2010 23:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-search-plan/m-p/12549#M64</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-05-03T23:10:26Z</dc:date>
    </item>
  </channel>
</rss>

