<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Fields Efficiently in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54982#M13406</link>
    <description>&lt;P&gt;If you really want to go that way, use the search inspector (the "i" button) to see the search speed.&lt;BR /&gt;
and run the same search on the same time window with several variations of your search.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Dec 2012 07:14:43 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2012-12-06T07:14:43Z</dc:date>
    <item>
      <title>Using Fields Efficiently</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54981#M13405</link>
      <description>&lt;P&gt;I'm trying to get a search to run as efficiently as possible and a couple of the guys on my team have been going back and forth regarding the placement of the 'fields' syntax.&lt;/P&gt;

&lt;P&gt;I have always put the 'fields' syntax immediately after my sourcetype, but some people put it in the middle of the search, some put it before/after the math that is done, some put it right before the 'stats', 'table', etc. &lt;/P&gt;

&lt;P&gt;I looked in the documentation, but I didn't see anything saying that it should go "here" or "there".&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Is there a preferred place to put the 'fields' syntax?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2012 15:49:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54981#M13405</guid>
      <dc:creator>peasead</dc:creator>
      <dc:date>2012-12-05T15:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using Fields Efficiently</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54982#M13406</link>
      <description>&lt;P&gt;If you really want to go that way, use the search inspector (the "i" button) to see the search speed.&lt;BR /&gt;
and run the same search on the same time window with several variations of your search.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2012 07:14:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54982#M13406</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-12-06T07:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Using Fields Efficiently</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54983#M13407</link>
      <description>&lt;P&gt;Great idea.&lt;/P&gt;

&lt;P&gt;As it turns out, it doesn't matter much.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2012 17:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Fields-Efficiently/m-p/54983#M13407</guid>
      <dc:creator>peasead</dc:creator>
      <dc:date>2012-12-06T17:05:30Z</dc:date>
    </item>
  </channel>
</rss>

