<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Optimize my search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453976#M128467</link>
    <description>&lt;P&gt;Ohh, thank you!&lt;BR /&gt;
It helps!!! &lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2019 07:11:19 GMT</pubDate>
    <dc:creator>jyab6z</dc:creator>
    <dc:date>2019-03-22T07:11:19Z</dc:date>
    <item>
      <title>Optimize my search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453974#M128465</link>
      <description>&lt;P&gt;This is my search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Function="- Parts::GetPartSection =&amp;gt;" | rex "maingroupNo\&amp;gt;(?.+)\\(?.+)\\(?.+)\" | convert timeformat="%H:%M:%S" dur2sec(TimeInSec) | stats count first(TimeInSec) AS endTime last(TimeInSec) AS startTime by UserID DATE maingroup subgroup | appendcols [search Function="- Parts::GetPartSection =&amp;gt;" | rex "maingroupNo\&amp;gt;(?.+)\\(?.+)\\(?.+)\"  | stats list(secId) as secId_new by UserID DATE maingroup subgroup] | where count &amp;gt; 5 | eval Time_diff = abs(endTime - startTime) | eval avgTime_count = Time_diff/count | where avgTime_count &amp;lt; 20 | where maingroup=="03" AND subgroup=="26" | mvexpand secId_new | stats count by secId_new | rename secId_new as Avsnitt
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;THEN got this error when it runs over 1 year's data.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6758i9E6CD54013E4B9E5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;BR /&gt;
Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 13:40:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453974#M128465</guid>
      <dc:creator>jyab6z</dc:creator>
      <dc:date>2019-03-21T13:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Optimize my search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453975#M128466</link>
      <description>&lt;P&gt;The subsearch is trying to process too much data. Why do you even need it?  You should be able to combine the two searches into a single search.  See if this accomplishes the same task.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Function="- Parts::GetPartSection =&amp;gt;" | rex "maingroupNo\&amp;gt;(?.+)\\(?.+)\\(?.+)\" | convert timeformat="%H:%M:%S" dur2sec(TimeInSec) | stats count first(TimeInSec) AS endTime, last(TimeInSec) AS startTime, list(secId) as secId_new by UserID DATE maingroup subgroup | where count &amp;gt; 5 | eval Time_diff = abs(endTime - startTime) | eval avgTime_count = Time_diff/count | where avgTime_count &amp;lt; 20 | where maingroup=="03" AND subgroup=="26" | mvexpand secId_new | stats count by secId_new | rename secId_new as Avsnitt
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Mar 2019 15:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453975#M128466</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-03-21T15:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Optimize my search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453976#M128467</link>
      <description>&lt;P&gt;Ohh, thank you!&lt;BR /&gt;
It helps!!! &lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 07:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Optimize-my-search/m-p/453976#M128467</guid>
      <dc:creator>jyab6z</dc:creator>
      <dc:date>2019-03-22T07:11:19Z</dc:date>
    </item>
  </channel>
</rss>

