<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic prestats vs stats in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195796#M56454</link>
    <description>&lt;P&gt;In $SPLUNK_HOME/var/run/splunk/dispatch/1312323432.11 is see:  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-19-2014 17:02:11.147 INFO  SearchParser - PARSING: litsearch index=_internal source="*license_usage.lo*" type=Usage  | bucket  _time span=10m   | eval  indexer_guid=i   | addinfo  type=count label=prereport_events  | fields  keepcolorder=t "_time" "b" "indexer_guid" "prestats_reserved_*" "psrsvd_*"  | prestats  sum(b) by _time indexer_guid
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the search.log file I see my stats command has been translated to prestats. Why is this? &lt;/P&gt;</description>
    <pubDate>Thu, 20 Mar 2014 00:07:40 GMT</pubDate>
    <dc:creator>rroberts</dc:creator>
    <dc:date>2014-03-20T00:07:40Z</dc:date>
    <item>
      <title>prestats vs stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195796#M56454</link>
      <description>&lt;P&gt;In $SPLUNK_HOME/var/run/splunk/dispatch/1312323432.11 is see:  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-19-2014 17:02:11.147 INFO  SearchParser - PARSING: litsearch index=_internal source="*license_usage.lo*" type=Usage  | bucket  _time span=10m   | eval  indexer_guid=i   | addinfo  type=count label=prereport_events  | fields  keepcolorder=t "_time" "b" "indexer_guid" "prestats_reserved_*" "psrsvd_*"  | prestats  sum(b) by _time indexer_guid
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the search.log file I see my stats command has been translated to prestats. Why is this? &lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 00:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195796#M56454</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2014-03-20T00:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: prestats vs stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195797#M56455</link>
      <description>&lt;P&gt;I'm fairly certain that's related to running as much as possible on the indexers during the map phase, and hence sending as little as possible to the searchhead for the reduce phase. This should not affect your searching... other than through blazing speed of course.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 14:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195797#M56455</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-21T14:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: prestats vs stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195798#M56456</link>
      <description>&lt;P&gt;Thanks, found more details here:&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://www.splunk.com/web_assets/pdfs/secure/Splunk_and_MapReduce.pdf"&gt;http://www.splunk.com/web_assets/pdfs/secure/Splunk_and_MapReduce.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 17:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/prestats-vs-stats/m-p/195798#M56456</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2014-03-21T17:41:28Z</dc:date>
    </item>
  </channel>
</rss>

