<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Most efficient: alot of smaller searches or one large one in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Most-efficient-alot-of-smaller-searches-or-one-large-one/m-p/105175#M27275</link>
    <description>&lt;P&gt;The single search is most probably the most efficient one.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Dec 2010 03:20:26 GMT</pubDate>
    <dc:creator>ziegfried</dc:creator>
    <dc:date>2010-12-16T03:20:26Z</dc:date>
    <item>
      <title>Most efficient: alot of smaller searches or one large one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Most-efficient-alot-of-smaller-searches-or-one-large-one/m-p/105174#M27274</link>
      <description>&lt;P&gt;Trying to find out what is most efficient in this scenario resource/time wise.&lt;/P&gt;

&lt;P&gt;We want to do a search across the last 90 days that looks for sshd and matching a user, to look for logins.&lt;/P&gt;

&lt;P&gt;Is it better to loop over a user list inputting a search for each user separately as 'earliest=-90d sshd user=$var_user' one at a time or to do one search with all the users OR'ed like so 'earliest=-90d sshd (user=$var_user OR user=$var_user1 OR....)'?&lt;/P&gt;

&lt;P&gt;This is in the context of the user list being hundreds of users long.  So are hundreds of stacked up long-length single-term searches better than lots and lots of ORs across the same time range in a single search.&lt;/P&gt;

&lt;P&gt;Thoughts?&lt;/P&gt;

&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2010 02:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Most-efficient-alot-of-smaller-searches-or-one-large-one/m-p/105174#M27274</guid>
      <dc:creator>skippylou</dc:creator>
      <dc:date>2010-12-16T02:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Most efficient: alot of smaller searches or one large one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Most-efficient-alot-of-smaller-searches-or-one-large-one/m-p/105175#M27275</link>
      <description>&lt;P&gt;The single search is most probably the most efficient one.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2010 03:20:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Most-efficient-alot-of-smaller-searches-or-one-large-one/m-p/105175#M27275</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2010-12-16T03:20:26Z</dc:date>
    </item>
  </channel>
</rss>

