<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard Best Practices &amp; Performance in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178888#M11069</link>
    <description>&lt;P&gt;Sure: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/AdvancedDev/PostProcess"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/AdvancedDev/PostProcess&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 08 Mar 2014 16:44:27 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-03-08T16:44:27Z</dc:date>
    <item>
      <title>Dashboard Best Practices &amp; Performance</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178885#M11066</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have a dashboard that displays around 30 saved searches.  I have it set to load all the saved searches when the dashboard is loaded and refresh every 600 seconds - performance is fair.  &lt;/P&gt;

&lt;P&gt;To increase performance, I'm debating on scheduling the saved searches but don't want to create too much overhead when the dashboard is not in use.  Would using dashboard inline searches be a better option?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2014 14:05:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178885#M11066</guid>
      <dc:creator>subtrakt</dc:creator>
      <dc:date>2014-03-08T14:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Best Practices &amp; Performance</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178886#M11067</link>
      <description>&lt;P&gt;Inline or saved searches don't affect their performance, that's just where the search string is stored.&lt;/P&gt;

&lt;P&gt;Some common ways to improve performance of a many-searches dashboard:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Look for commonality between searches. When found, combine several searches into one and use post-processing to drive several panels off one search.&lt;/LI&gt;
&lt;LI&gt;Look for searches eligible for report acceleration&lt;/LI&gt;
&lt;LI&gt;Look for long-running searches left over after these steps and schedule those searches&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Above all that there's general search performance optimization, such as reducing the number of events scanned to achieve the search goal or replacing costly operations with cheaper ones or avoiding inefficient wildcard matches.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2014 15:17:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178886#M11067</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-08T15:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Best Practices &amp; Performance</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178887#M11068</link>
      <description>&lt;P&gt;Is there doc on how to handle post-processing?&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2014 16:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178887#M11068</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-03-08T16:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Best Practices &amp; Performance</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178888#M11069</link>
      <description>&lt;P&gt;Sure: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/AdvancedDev/PostProcess"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/AdvancedDev/PostProcess&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2014 16:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Best-Practices-Performance/m-p/178888#M11069</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-08T16:44:27Z</dc:date>
    </item>
  </channel>
</rss>

