<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Search Optimization in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Optimization/m-p/698549#M237196</link>
    <description>&lt;P&gt;Hi Team,&lt;BR /&gt;As per business requirement, need to get below details from same autosys batch and corresponding outputs to be displayed on the single row in a table:&lt;BR /&gt;1. Last execution time&amp;nbsp;&lt;BR /&gt;2. Execution time of specific search keyword i.e., Completed invokexPressionJob and obtained queue id ::&lt;BR /&gt;3. Number of times "ERROR" keyword present&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;"    
| stats latest(_time) as  latest_time 
| convert ctime(latest_time)  
| append [search index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;" 
| search "Completed invokexPressionJob and obtained queue id ::"    
| stats latest(_time) as last_success_time 
| convert ctime(last_success_time)]   
| append [search index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;" 
| rex field=_raw "\s(?P&amp;lt;level&amp;gt;[^\/]+)\s\[main\]"  
| stats count(level) by level 
| WHERE level IN ("ERROR")] | append [| makeresults | eval job_name="Print Job"] 
| table  latest_time last_success_time count(level) job_name
| stats list(*) as *&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;Above query works fine. From query performance prospective, am I achieving the output right way? Is there any other better to achieve it? Because, similar set to query I need to apply to 10 other batch jobs inside the Splunk dashboard. Kindly suggest!!&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2024 18:06:21 GMT</pubDate>
    <dc:creator>ganeshkumarmoha</dc:creator>
    <dc:date>2024-09-09T18:06:21Z</dc:date>
    <item>
      <title>Splunk Search Optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Optimization/m-p/698549#M237196</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;As per business requirement, need to get below details from same autosys batch and corresponding outputs to be displayed on the single row in a table:&lt;BR /&gt;1. Last execution time&amp;nbsp;&lt;BR /&gt;2. Execution time of specific search keyword i.e., Completed invokexPressionJob and obtained queue id ::&lt;BR /&gt;3. Number of times "ERROR" keyword present&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;"    
| stats latest(_time) as  latest_time 
| convert ctime(latest_time)  
| append [search index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;" 
| search "Completed invokexPressionJob and obtained queue id ::"    
| stats latest(_time) as last_success_time 
| convert ctime(last_success_time)]   
| append [search index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;" 
| rex field=_raw "\s(?P&amp;lt;level&amp;gt;[^\/]+)\s\[main\]"  
| stats count(level) by level 
| WHERE level IN ("ERROR")] | append [| makeresults | eval job_name="Print Job"] 
| table  latest_time last_success_time count(level) job_name
| stats list(*) as *&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;Above query works fine. From query performance prospective, am I achieving the output right way? Is there any other better to achieve it? Because, similar set to query I need to apply to 10 other batch jobs inside the Splunk dashboard. Kindly suggest!!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 18:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Optimization/m-p/698549#M237196</guid>
      <dc:creator>ganeshkumarmoha</dc:creator>
      <dc:date>2024-09-09T18:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Optimization</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Optimization/m-p/698593#M237225</link>
      <description>&lt;P class="lia-align-left"&gt;Using append is almost never the right solution - you are performing the same search three times and just collecting bits of info each time - this can be done in one search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="&amp;lt;indexid&amp;gt;" Appid="&amp;lt;appid&amp;gt;" host IN (&amp;lt;host01&amp;gt;) source="&amp;lt;log_path01&amp;gt;" 
| eval success_time=if(searchmatch("Completed invokexPressionJob and obtained queue id ::"), _time, null())
| rex field=_raw "\s(?P&amp;lt;level&amp;gt;[^\/]+)\s\[main\]" 

| stats latest(_time) as latest_time latest(success_time) as success_time sum(eval(if(level="ERROR",1, 0))) as errors
| convert ctime(latest_time) 
| convert ctime(success_time)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;success_time is determined if the event matches the criteria wanted and errors are calculated if the level is ERROR.&lt;/P&gt;&lt;P&gt;Not sure what you're trying to do with the final append with Print Job on a new row.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 22:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Optimization/m-p/698593#M237225</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-09-09T22:06:24Z</dc:date>
    </item>
  </channel>
</rss>

