<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search optimization in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/638526#M221271</link>
    <description>&lt;P&gt;Made some changes&lt;BR /&gt;environment=test earliest=@d+5h latest=@d+9h (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) cs_method=POST | regex cs_uri_stem=(?i)"/account/v1/login/forgot-password"| bin _time span=1m | stats count as RPM by _time | eval TPS=RPM/60 | stats max(TPS) as&lt;BR /&gt;MaxTPS&lt;BR /&gt;it is still taking 56 secs for this query to run , here is the results from inspect job&lt;BR /&gt;&lt;BR /&gt;Duration(sec) Component&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Invocations Input count Output count&lt;BR /&gt;2.45&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.prestats&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3,258&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15,495&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 8,954&lt;BR /&gt;34.23&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.regex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3,258&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32,047,620 15,495&lt;BR /&gt;3.73&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.remotetl&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3,258&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15,495&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15,495&lt;BR /&gt;2,383.81&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6,516&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 32,047,620 64,095,240&lt;BR /&gt;57.63&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.calcfields 9,202 32,196,524 32,196,524&lt;BR /&gt;2.74&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.expand_search 56 - -&lt;BR /&gt;77.43&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.fieldalias 9,202 32,196,524 32,196,524&lt;BR /&gt;26.30&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.filter 9,202 32,196,524 32,047,620&lt;BR /&gt;22.42&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.index 9,539 - -&lt;BR /&gt;312.24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.kv 9,202 - -&lt;BR /&gt;246.08 command.search.lookups 9,202 32,196,524 32,196,524&lt;BR /&gt;155.64 command.search.rawdata 9,202 - -&lt;BR /&gt;1,358.04 command.search.typer 9,202 32,047,620 32,047,620&lt;BR /&gt;61.37 command.search.tags 9,202 32,047,620 32,047,620&lt;BR /&gt;7.24 command.search.track_sourcetypes 3,258 - -&lt;BR /&gt;2,424.81 dispatch.stream.remote 3,257 - 69,230,943&lt;BR /&gt;&lt;BR /&gt;This is phase0 search query from inspect job&lt;BR /&gt;&lt;SPAN&gt;litsearch (cs_method=POST (__f!=v OR environment=prod) (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) (index!=dp_sec_log OR index!=log-vdi-prod OR index!=idm-win-other OR index!=www_app OR index!=www_app) _time&amp;gt;=1680523200.000 _time&amp;lt;1680537600.000) | litsearch (cs_method=POST environment=prod (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) (index!=dp_sec_log OR index!=log-vdi-prod OR index!=idm-win-other OR index!=www_app OR index!=www_app) _time&amp;gt;=1680523200.000 _time&amp;lt;1680537600.000) | regex cs_uri_stem=(?i)"/account/v1/login/forgot-password" | bin _time span=1m | addinfo type=count label=prereport_events track_fieldmeta_events=true | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "_time" "host" "index" "linecount" "prestats_reserved_*" "psrsvd_*" "source" "sourcetype" "splunk_server" | remotetl nb=300 et=1680523200.000000 lt=1680537600.000000 max_count=1000 max_prefetch=100 | prestats count by _time&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2023 21:33:14 GMT</pubDate>
    <dc:creator>msrama5</dc:creator>
    <dc:date>2023-04-03T21:33:14Z</dc:date>
    <item>
      <title>Are there way to optimize this query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636786#M221138</link>
      <description>&lt;P&gt;Hello, following query is slow and processing a lot of data&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;environment=tesxt earliest=-0d@d (index=iis_openapi OR index=iis OR index=iis1 ) cs_method=POST | regex cs_uri_stem=(?i)"/account/v1/login/forgot-password" |eval Hour=strftime(_time,"%H")|search Hour&amp;gt;=5 AND Hour&amp;lt;9| bin _time span=60s | stats count as RPM by _time | eval TPS=RPM/60 | stats max(TPS) as MaxTPS&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there way to optimize this query ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 14:13:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636786#M221138</guid>
      <dc:creator>msrama5</dc:creator>
      <dc:date>2023-04-11T14:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636790#M221139</link>
      <description>&lt;P&gt;this looks like a straight forward search query.. not much fine-tuning can be done.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;earliest=-0d@d ---- you meant to run this search query from midnight today to the current time, right (for example.. if you run this query at 7am meaning.. u r searching for 0am to 7am...is that right?!?!)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;as per my knowledge, the only fine tuning ...ie, the search optimization that can be done for this query is .. the summary indexing.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Knowledge/Usesummaryindexing" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Knowledge/Usesummaryindexing&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 00:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636790#M221139</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-03-31T00:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636791#M221140</link>
      <description>&lt;P&gt;If your ingestion is auto extracting date_hour and other date_* fields than you can put the hour filter in the initial search part.&lt;/P&gt;&lt;P&gt;Is your cs_uri_stem search looking for that anywhere in the uri or an exact match - just wondering if that can be part of the search too.&lt;/P&gt;&lt;P&gt;Also, I forget it IIS logs have those fields as quoted or if they are in the logs as unquoted. If they are unquoted, then you may be able to use TERM, i.e.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TERM(environment=tesxt) TERM(cs_method=POST)&lt;/LI-CODE&gt;&lt;P&gt;which would probably reduce the data pulled from disk.&lt;/P&gt;&lt;P&gt;Have you looked at the job inspector to see where the time is being spent and what the phase0 search is converted to?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 01:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636791#M221140</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-31T01:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636815#M221147</link>
      <description>&lt;P&gt;Since you are only looking for events between 5am and 9am, try using&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;earliest=@d+5h latest=@d+9h&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 31 Mar 2023 05:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/636815#M221147</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-31T05:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/638451#M221270</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;This is where it it taking more time from inspect job&lt;/P&gt;&lt;P&gt;Duration (seconds) Component&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Invocations Input count Output count&lt;BR /&gt;2,133.38&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6,598&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 32,047,620&amp;nbsp; 64,095,240&lt;BR /&gt;52.30&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.calcfields&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 32,196,524 32,196,524&lt;BR /&gt;0.00&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.evalfilter&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 32,196,524 32,196,524&lt;BR /&gt;69.98&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.fieldalias&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32,196,524 32,196,524&lt;BR /&gt;23.20&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.filter&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 32,196,524 32,047,620&lt;BR /&gt;213.23&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.lookups&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32,196,524 32,196,524&lt;BR /&gt;1,219.75&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.typer&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32,047,620 32,047,620&lt;BR /&gt;56.40&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.tags&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9,307&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32,047,620 32,047,620&lt;BR /&gt;6.95&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.track_sourcetypes&amp;nbsp; &amp;nbsp;3,299&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&lt;BR /&gt;0.01&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dispatch.preview.write_results_to_disk 30&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&lt;BR /&gt;7.64&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dispatch.process_remote_timeline&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1,860 19,383,546&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&lt;BR /&gt;3.95&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dispatch.remote_timeline_fullevents&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1,034 11,207,755&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 5,400&lt;BR /&gt;0.00&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dispatch.stream.local&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&lt;BR /&gt;2,171.22&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dispatch.stream.remote&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3,298&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;70,330,684&lt;BR /&gt;31.46&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;command.regex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;3,299&amp;nbsp;&amp;nbsp;32,047,620&amp;nbsp; &amp;nbsp; &amp;nbsp; 15495&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Following is phase0 search value from job inspector&lt;BR /&gt;&lt;SPAN&gt;litsearch (cs_method=POST (__f!=v OR environment=prod) (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) (index!=dp_sec_log OR index!=log-vdi-prod OR index!=idm-win-other OR index!=www_app OR index!=www_app) _time&amp;gt;=1680523200.000 _time&amp;lt;1680537600.000) | litsearch (cs_method=POST environment=prod (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) (index!=dp_sec_log OR index!=log-vdi-prod OR index!=idm-win-other OR index!=www_app OR index!=www_app) _time&amp;gt;=1680523200.000 _time&amp;lt;1680537600.000) | regex cs_uri_stem=(?i)"/account/v1/login/forgot-password" | eval Hour=strftime('_time',"%H") | bin _time span=1m | addinfo type=count label=prereport_events track_fieldmeta_events=true | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "_time" "host" "index" "linecount" "prestats_reserved_*" "psrsvd_*" "source" "sourcetype" "splunk_server" | remotetl nb=300 et=1680523200.000000 lt=1680537600.000000 max_count=1000 max_prefetch=100 | prestats count by _time&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 20:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/638451#M221270</guid>
      <dc:creator>msrama5</dc:creator>
      <dc:date>2023-04-03T20:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/638526#M221271</link>
      <description>&lt;P&gt;Made some changes&lt;BR /&gt;environment=test earliest=@d+5h latest=@d+9h (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) cs_method=POST | regex cs_uri_stem=(?i)"/account/v1/login/forgot-password"| bin _time span=1m | stats count as RPM by _time | eval TPS=RPM/60 | stats max(TPS) as&lt;BR /&gt;MaxTPS&lt;BR /&gt;it is still taking 56 secs for this query to run , here is the results from inspect job&lt;BR /&gt;&lt;BR /&gt;Duration(sec) Component&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Invocations Input count Output count&lt;BR /&gt;2.45&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.prestats&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3,258&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15,495&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 8,954&lt;BR /&gt;34.23&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.regex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3,258&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32,047,620 15,495&lt;BR /&gt;3.73&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.remotetl&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3,258&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15,495&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15,495&lt;BR /&gt;2,383.81&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6,516&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 32,047,620 64,095,240&lt;BR /&gt;57.63&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.calcfields 9,202 32,196,524 32,196,524&lt;BR /&gt;2.74&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.expand_search 56 - -&lt;BR /&gt;77.43&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.fieldalias 9,202 32,196,524 32,196,524&lt;BR /&gt;26.30&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.filter 9,202 32,196,524 32,047,620&lt;BR /&gt;22.42&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;command.search.index 9,539 - -&lt;BR /&gt;312.24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; command.search.kv 9,202 - -&lt;BR /&gt;246.08 command.search.lookups 9,202 32,196,524 32,196,524&lt;BR /&gt;155.64 command.search.rawdata 9,202 - -&lt;BR /&gt;1,358.04 command.search.typer 9,202 32,047,620 32,047,620&lt;BR /&gt;61.37 command.search.tags 9,202 32,047,620 32,047,620&lt;BR /&gt;7.24 command.search.track_sourcetypes 3,258 - -&lt;BR /&gt;2,424.81 dispatch.stream.remote 3,257 - 69,230,943&lt;BR /&gt;&lt;BR /&gt;This is phase0 search query from inspect job&lt;BR /&gt;&lt;SPAN&gt;litsearch (cs_method=POST (__f!=v OR environment=prod) (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) (index!=dp_sec_log OR index!=log-vdi-prod OR index!=idm-win-other OR index!=www_app OR index!=www_app) _time&amp;gt;=1680523200.000 _time&amp;lt;1680537600.000) | litsearch (cs_method=POST environment=prod (index=iis_openapi OR index=iis_securehostopenapi OR index=iis_securepayment) (index!=dp_sec_log OR index!=log-vdi-prod OR index!=idm-win-other OR index!=www_app OR index!=www_app) _time&amp;gt;=1680523200.000 _time&amp;lt;1680537600.000) | regex cs_uri_stem=(?i)"/account/v1/login/forgot-password" | bin _time span=1m | addinfo type=count label=prereport_events track_fieldmeta_events=true | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "_time" "host" "index" "linecount" "prestats_reserved_*" "psrsvd_*" "source" "sourcetype" "splunk_server" | remotetl nb=300 et=1680523200.000000 lt=1680537600.000000 max_count=1000 max_prefetch=100 | prestats count by _time&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 21:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/638526#M221271</guid>
      <dc:creator>msrama5</dc:creator>
      <dc:date>2023-04-03T21:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/639447#M221556</link>
      <description>&lt;P&gt;Have you tried putting the cs_uri_stem search criteria into the search statement rather than in the regex?&lt;/P&gt;&lt;P&gt;Also, can you show an example of what the _raw data looks like for one of those events - to see if you can make use of TERM() statements.&lt;/P&gt;&lt;P&gt;You can see that this&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1,358.04 command.search.typer 9,202 32,047,620 32,047,620&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;appears to be taking a significant part of that time and there are 32 million events going into it. That is the time spent creating event types. If you have broad sharing of many eventtypes I suspect that may negatively affect performance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you have 32 million forgot password requests? I suspect not, so you need to see how you can reduce the data coming off disk - TERM and the cs_uri_stem in the search may help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 05:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/639447#M221556</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-04-11T05:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Search optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/639448#M221557</link>
      <description>&lt;P&gt;Also, are you using datamodels and if so, do you have the web datamodel in use and is it accelerated. If so you can use tstats, but if not, you can't&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 05:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-way-to-optimize-this-query/m-p/639448#M221557</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-04-11T05:45:44Z</dc:date>
    </item>
  </channel>
</rss>

