<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unique KeyValue search performance in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125961#M34072</link>
    <description>&lt;P&gt;Thanks for that, interesting read. I have since set up the index-time field extraction after a fair amount of pain and running the following command now takes between 100-200ms, what a difference!&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;search sourcetype=sourcetypeid KeyID::1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jan 2014 09:15:11 GMT</pubDate>
    <dc:creator>splunkrg</dc:creator>
    <dc:date>2014-01-27T09:15:11Z</dc:date>
    <item>
      <title>Unique KeyValue search performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125958#M34069</link>
      <description>&lt;P&gt;Hey Everyone,&lt;/P&gt;

&lt;P&gt;I'm having a bit of trouble with Splunk search performance, I currently have around 1 million rows of logs, each row approx 1kb wide that conforms to the following pattern:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;SomeKey1="stringdata" SomeKey2="stringdata" SomeKey3="stringdata" KeyID="UniqueNumericID"&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;When I do a search on this data using a simple search query such as:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;search sourcetype=sourcetypeid KeyID="1"&lt;/EM&gt;&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;It takes up to 20-30secs to return the single matching event on a dedicated server (quad core xeon, 16gb ram, SATA3 SSD) using either the GUI or via the REST API. After inspecting many similar queries jobs, the largest consumer of time seems to be &lt;EM&gt;dispatch.fetch&lt;/EM&gt; / &lt;EM&gt;dispatch.stream.local&lt;/EM&gt;, when you take into account that I need to do this similar queries very often and programmatically, I assume the best thing to do would be extract the KeyID field at index time, would this drastically improve the search speed? Are there any other pitfalls that I may have missed?&lt;/P&gt;

&lt;P&gt;Thanks in advance..&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2014 04:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125958#M34069</guid>
      <dc:creator>splunkrg</dc:creator>
      <dc:date>2014-01-26T04:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unique KeyValue search performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125959#M34070</link>
      <description>&lt;P&gt;Are you actually looking for a value "1" or is that just an example?&lt;/P&gt;

&lt;P&gt;If you are, Splunk is first loading all events containing "1" and then matching them against the field you were looking for - that's not very efficient, because I assume there are many events containing "1" where KeyID isn't "1".&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2014 10:40:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125959#M34070</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-26T10:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unique KeyValue search performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125960#M34071</link>
      <description>&lt;P&gt;As martin_mueller says, it's important to know here how unique the KeyID values are - that is, not only in this specific sourcetype, but across all data in the index.&lt;/P&gt;

&lt;P&gt;@dwaddle has explained very well the specifics of what goes on in a Splunk search here: &lt;A href="http://answers.splunk.com/answers/54207/slow-search-when-evaluating-a-numeric-value?page=1&amp;amp;focusedAnswerId=54224#54224"&gt;http://answers.splunk.com/answers/54207/slow-search-when-evaluating-a-numeric-value?page=1&amp;amp;focusedAnswerId=54224#54224&lt;/A&gt;&lt;BR /&gt;
It's a very good read and I think it answers your question. Short version here: KeyID="1" will be slow because "1" is very likely such a common token in your index, and as most fields aren't extracted until at at search-time, when you search for KeyID="1" Splunk will in practice find all events with the token "1" in them and THEN see if any of these tokens can be matched to the field "KeyID". In this scenario an index-time field extraction &lt;EM&gt;might&lt;/EM&gt; be a good idea in order to improve performance.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2014 20:09:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125960#M34071</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-01-26T20:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unique KeyValue search performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125961#M34072</link>
      <description>&lt;P&gt;Thanks for that, interesting read. I have since set up the index-time field extraction after a fair amount of pain and running the following command now takes between 100-200ms, what a difference!&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;search sourcetype=sourcetypeid KeyID::1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 09:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unique-KeyValue-search-performance/m-p/125961#M34072</guid>
      <dc:creator>splunkrg</dc:creator>
      <dc:date>2014-01-27T09:15:11Z</dc:date>
    </item>
  </channel>
</rss>

