<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: using field in timechart queries in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/using-field-in-timechart-queries/m-p/129914#M7661</link>
    <description>&lt;P&gt;I believe that the &lt;CODE&gt;timechart&lt;/CODE&gt; command will remove all unnecessary information. &lt;/P&gt;

&lt;P&gt;What you could do is to ensure that your question before the &lt;CODE&gt;timechart&lt;/CODE&gt; runs as efficiently as possible, e.g. specifying the correct index and sourcetype, search only for the time range you're interested in. You could even instruct Splunk to not extract any fields at all (&lt;CODE&gt;KV_MODE = none&lt;/CODE&gt; in props.conf), and only extract what you need with (an efficient) &lt;CODE&gt;rex&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
    <pubDate>Sun, 13 Apr 2014 19:35:43 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2014-04-13T19:35:43Z</dc:date>
    <item>
      <title>using field in timechart queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/using-field-in-timechart-queries/m-p/129913#M7660</link>
      <description>&lt;P&gt;I have a dashboard with many panels.  If i used the 'field' command for for the underlying queries, would that help save Splunk resources? &lt;/P&gt;

&lt;P&gt;Or does Splunk already know what field to use when it see's 'timechart count by &lt;FIELD&gt;' and then ignores the rest of the fields???&lt;/FIELD&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Apr 2014 17:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/using-field-in-timechart-queries/m-p/129913#M7660</guid>
      <dc:creator>subtrakt</dc:creator>
      <dc:date>2014-04-13T17:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: using field in timechart queries</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/using-field-in-timechart-queries/m-p/129914#M7661</link>
      <description>&lt;P&gt;I believe that the &lt;CODE&gt;timechart&lt;/CODE&gt; command will remove all unnecessary information. &lt;/P&gt;

&lt;P&gt;What you could do is to ensure that your question before the &lt;CODE&gt;timechart&lt;/CODE&gt; runs as efficiently as possible, e.g. specifying the correct index and sourcetype, search only for the time range you're interested in. You could even instruct Splunk to not extract any fields at all (&lt;CODE&gt;KV_MODE = none&lt;/CODE&gt; in props.conf), and only extract what you need with (an efficient) &lt;CODE&gt;rex&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Sun, 13 Apr 2014 19:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/using-field-in-timechart-queries/m-p/129914#M7661</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-04-13T19:35:43Z</dc:date>
    </item>
  </channel>
</rss>

