<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Some One Help With Query Optimization in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459992#M129776</link>
    <description>&lt;P&gt;why don't you stop use &lt;CODE&gt;join&lt;/CODE&gt; and make flag like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval flag=case(parsedate &amp;gt; relative_time(now(),"-10d@d") AND parsedate &amp;lt; now() ,"lastdate", ....)
 ....
| stats sum(AMOUNT) as AMOUNT by UiCountryCode parsedate flag
...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 19 May 2020 14:14:22 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-05-19T14:14:22Z</dc:date>
    <item>
      <title>Can Some One Help With Query Optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459990#M129774</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index="ocdm" source IN ("covid_collection.csv","covid_collection_lcpr.csv","covid_collection_cl.csv", "covid_collection_cr.csv") 
|where AMOUNT!="NA" 
|eval latestdatestart=relative_time(now(),"-10d@d"),latestdateend=now(),parsedate=strptime(TXNDATE,"%m/%d/%Y")
|where parsedate &amp;gt;= latestdatestart AND parsedate &amp;lt; latestdateend  
|stats sum(AMOUNT) as latestdatevalue  by UiCountryCode parsedate|sort parsedate 
|eval latestdate=strftime(parsedate,"%m/%d/%Y"), latestdatevalue=round(latestdatevalue,2) 
| table UiCountryCode latestdate latestdatevalue lastday |eval latestdateformat=strptime(latestdate,"%m/%d/%Y"),lastdayformat = relative_time(latestdateformat,"-1d@d"),lastday=strftime(lastdayformat,"%m/%d/%Y")
|join UiCountryCode lastday [search index="ocdm" source IN ("covid_collection.csv","covid_collection_lcpr.csv","covid_collection_cl.csv", "covid_collection_cr.csv") 
  |where AMOUNT!="NA"
  |eval lastdaystart=relative_time(now(),"-11d@d"),lastdayend=relative_time(now(),"-1d@d"),parsedate=strptime(TXNDATE,"%m/%d/%Y")
  |where parsedate &amp;gt;= lastdaystart AND parsedate &amp;lt; lastdayend |stats sum(AMOUNT) as lastdayvalue  by UiCountryCode parsedate
  |sort parsedate
  |eval lastday=strftime(parsedate,"%m/%d/%Y"),lastdayvalue=round(lastdayvalue,2) 
  | table UiCountryCode lastday lastdayvalue
  |eval lastdayformat=strptime(lastday,"%m/%d/%Y"),lastweekformat = 
  relative_time(lastdayformat,"-7d@d"),lastweek=strftime(lastweekformat,"%m/%d/%Y")]
|join UiCountryCode lastweek[search index="ocdm" source IN ("covid_collection.csv","covid_collection_lcpr.csv","covid_collection_cl.csv", "covid_collection_cr.csv") 
  |where AMOUNT!="NA"
  |eval lastweekstart=relative_time(now(),"-17d@d"),lastweekend=relative_time(now(),"-6d@d"),parsedate=strptime(TXNDATE,"%m/%d/%Y")
  |where parsedate &amp;gt;= lastweekstart AND parsedate &amp;lt; lastweekend  
  |stats sum(AMOUNT) as lastweekvalue  by UiCountryCode parsedate
  |sort parsedate
  |eval lastweek=strftime(parsedate,"%m/%d/%Y"),lastweekvalue=round(lastweekvalue,2)
  | table UiCountryCode lastweek lastweekvalue]
|eval kpi="COLLECTION AMOUNT",_time=relative_time(now(),"-0d")
|fields - latestdateformat,- lastweekformat,- lastdayformat
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 May 2020 10:37:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459990#M129774</guid>
      <dc:creator>rakesh868852914</dc:creator>
      <dc:date>2020-05-19T10:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can Some One Help With Query Optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459991#M129775</link>
      <description>&lt;P&gt;I've reformatted the query to make it easier to read.&lt;/P&gt;

&lt;P&gt;Please explain what the query is attempting to do.  What are the desired results?  What makes you think it needs to be optimized?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 13:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459991#M129775</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-19T13:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can Some One Help With Query Optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459992#M129776</link>
      <description>&lt;P&gt;why don't you stop use &lt;CODE&gt;join&lt;/CODE&gt; and make flag like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval flag=case(parsedate &amp;gt; relative_time(now(),"-10d@d") AND parsedate &amp;lt; now() ,"lastdate", ....)
 ....
| stats sum(AMOUNT) as AMOUNT by UiCountryCode parsedate flag
...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 May 2020 14:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Some-One-Help-With-Query-Optimization/m-p/459992#M129776</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-19T14:14:22Z</dc:date>
    </item>
  </channel>
</rss>

