<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is my stats by command so slow and how can I speed it up for longer time intervals? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352574#M104379</link>
    <description>&lt;P&gt;Heya @timbCFCA, if DalJeanis solved your problem, please don't forget to accept an answer! You can upvote posts as well. (Karma points will be awarded for either action.) Happy Splunking!&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2017 23:08:02 GMT</pubDate>
    <dc:creator>lfedak_splunk</dc:creator>
    <dc:date>2017-09-21T23:08:02Z</dc:date>
    <item>
      <title>Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352571#M104376</link>
      <description>&lt;P&gt;I'm working on some statistics related queries. I'm trying to get the security id, date and count of hosts connected to.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=wineventlog sourcetype="WinEventLog:Security" 4624 |
fields host,Security_ID,_time  | 
bucket _time span=1d | 
stats dc(host) by Security_ID, _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;They work perfectly until I start adding Security_ID. With no &lt;CODE&gt;by&lt;/CODE&gt; command or only based on time it's fast.&lt;/P&gt;

&lt;P&gt;I also tried to do a  &lt;CODE&gt;dedup Security_ID, _time, host&lt;/CODE&gt; before the stats dc command but it didn't help the overall speed. &lt;/P&gt;

&lt;P&gt;It takes well over 10 minutes to complete this search for a week, and I'd like to be able to run this for 30 60 or 90 days. What do I need to do for that to be viable? &lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 18:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352571#M104376</guid>
      <dc:creator>timbCFCA</dc:creator>
      <dc:date>2017-09-20T18:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352572#M104377</link>
      <description>&lt;P&gt;How often are you running the search?  If you are running it fairly often, then you might consider a summary index so you don't have to re-spin the whole search multiple times a day.&lt;/P&gt;

&lt;P&gt;Try this - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=wineventlog sourcetype="WinEventLog:Security" 4624 
| fields host, Security_ID, _time  
| eval _time=floor(_time/86400)*86400
| dedup host,Security_ID,_time
| stats dc(host) by Security_ID, _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Explanation - &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;eval&lt;/CODE&gt; is streaming and distributed,  while &lt;CODE&gt;bin&lt;/CODE&gt; is not.  This way, the binning can be done at the individual indexers.&lt;/P&gt;

&lt;P&gt;Try it with and without the &lt;CODE&gt;dedup&lt;/CODE&gt; and see what happens.   &lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 19:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352572#M104377</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-20T19:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352573#M104378</link>
      <description>&lt;P&gt;Seems puzzling, I do see that Security_ID gets used as a source key several times in transforms.conf in the TA, I wonder if that causes any overhead. Maybe try specifying EventCode=4624 so that it isn't searching through all fields looking for 4624.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 02:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352573#M104378</guid>
      <dc:creator>worshamn</dc:creator>
      <dc:date>2017-09-21T02:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352574#M104379</link>
      <description>&lt;P&gt;Heya @timbCFCA, if DalJeanis solved your problem, please don't forget to accept an answer! You can upvote posts as well. (Karma points will be awarded for either action.) Happy Splunking!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 23:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352574#M104379</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-09-21T23:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352575#M104380</link>
      <description>&lt;P&gt;@timbCFCA - Did this change the run time at all?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 13:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352575#M104380</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-25T13:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352576#M104381</link>
      <description>&lt;P&gt;@DalJeanis not really. It did let me save as an accelerated search which helps. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 13:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352576#M104381</guid>
      <dc:creator>timbCFCA</dc:creator>
      <dc:date>2017-09-25T13:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my stats by command so slow and how can I speed it up for longer time intervals?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352577#M104382</link>
      <description>&lt;P&gt;@timbCFCA - Well, that's a decent consolation prize.&lt;/P&gt;

&lt;P&gt;Did you try it without the &lt;CODE&gt;dedup&lt;/CODE&gt;, which is redundant with the &lt;CODE&gt;dc()&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2017 21:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-stats-by-command-so-slow-and-how-can-I-speed-it-up-for/m-p/352577#M104382</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-26T21:14:17Z</dc:date>
    </item>
  </channel>
</rss>

