<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Optimizing Dashboard Searches in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Optimizing-Dashboard-Searches/m-p/73627#M3972</link>
    <description>&lt;P&gt;What I did pre-searches so that I can display the data in two ways, a sumary and a more granularity.  I was able to cut my searches in half.  I also ran into the limit of the graphing display, so instead of setting a time limit, I let the graphing program do more of the work. I was also running into the 10,000 limit for GUI&lt;/P&gt;&lt;BR /&gt;
I was also able to merge several time ranges into one view by use of a time selector.&lt;P&gt;&lt;/P&gt;&lt;BR /&gt;
In general I learned a bit since I posted this, and wanted to close the question.&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2011 12:59:03 GMT</pubDate>
    <dc:creator>fk319</dc:creator>
    <dc:date>2011-07-25T12:59:03Z</dc:date>
    <item>
      <title>Optimizing Dashboard Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Optimizing-Dashboard-Searches/m-p/73626#M3971</link>
      <description>&lt;P&gt;I have a dashboard that has 9 searches.  I currently extract my graph from 6 Summary Indexes.  5 of the Summary Indexes come from the same data set and 3 of the searches is the exact same data except that it is grouped.&lt;/P&gt;

&lt;P&gt;0) I have done a pre-search for the 3 pairs of data.  (aka I have figured out how to methods, barely)&lt;/P&gt;

&lt;P&gt;1) I would like to get this to 3 searches so that normal users can display the dashboard.  What constitutes a search: a data base search? or does the post search also count?&lt;/P&gt;

&lt;P&gt;2) I did some rough counts, If I merge the 5 summary-indexes into one, there will be about 300 events per minute.  Does this help or hurt the dashboard?&lt;/P&gt;

&lt;P&gt;3) Some of the charts I can only get 2 hours worth of data to display instead of 4 which the others can get, I don't know where I am running into this limitation.  (I get everything when I do the origional dashboard with 9 searches.)&lt;/P&gt;

&lt;P&gt;4) when doing a pre-search on the dashboard can you do a double pre-search?  This would help the pairs of data I refered to above.&lt;/P&gt;

&lt;P&gt;I feel that I am running into some road blocks as I am transfering my view form simple to optimized.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 19:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Optimizing-Dashboard-Searches/m-p/73626#M3971</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2010-10-20T19:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Optimizing Dashboard Searches</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Optimizing-Dashboard-Searches/m-p/73627#M3972</link>
      <description>&lt;P&gt;What I did pre-searches so that I can display the data in two ways, a sumary and a more granularity.  I was able to cut my searches in half.  I also ran into the limit of the graphing display, so instead of setting a time limit, I let the graphing program do more of the work. I was also running into the 10,000 limit for GUI&lt;/P&gt;&lt;BR /&gt;
I was also able to merge several time ranges into one view by use of a time selector.&lt;P&gt;&lt;/P&gt;&lt;BR /&gt;
In general I learned a bit since I posted this, and wanted to close the question.&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2011 12:59:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Optimizing-Dashboard-Searches/m-p/73627#M3972</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2011-07-25T12:59:03Z</dc:date>
    </item>
  </channel>
</rss>

