<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there set guidelines for Splunk search best practices, and are there any other resources on this topic? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234001#M69544</link>
    <description>&lt;P&gt;Yeah I had a feeling that it was going to be a large topic, given that I couldn't think of a way to encapsulate it in a straight forward question. Thank you for your insight though, this is all great information that I can go back to my team with and we can work on creating a plan to move forward with any changes that we need. And if you can think of any other important areas to look out for , please feel free to let me know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Mar 2016 19:09:00 GMT</pubDate>
    <dc:creator>ianbruton</dc:creator>
    <dc:date>2016-03-04T19:09:00Z</dc:date>
    <item>
      <title>Are there set guidelines for Splunk search best practices, and are there any other resources on this topic?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/233998#M69541</link>
      <description>&lt;P&gt;I am not sure exactly how to ask this question, so I will try to just dive right in.&lt;/P&gt;

&lt;P&gt;Background:&lt;BR /&gt;
I work for a company that has a lot of environments for different customers. The hosts in these environments are all feeding their logs Splunk via a forwarder installed on each host. We have started to utilize Splunk more and more over the last few months by setting up alerts and dashboards and such, which is putting more load on the Splunk infrastructure.&lt;/P&gt;

&lt;P&gt;Issue:&lt;BR /&gt;
I wanted to see if there was any set of guidelines for how you we should be using Splunk. Is there a right way and a wrong way to write a search, e.g. Are there methods that we should avoid using because they are inefficient and you can get the same results with a search that has been thought out more? &lt;/P&gt;

&lt;P&gt;Getting down to brass tacks, it looks like more and more of our monitoring is going to be handled by Splunk and I don't want it to become this big bloated monster. I want to try and see if we can streamline what we are already doing before we add more checks (and more importantly reliance) onto the system.&lt;/P&gt;

&lt;P&gt;I have been going through some of the posts that are already on here and some of the submissions on this page: &lt;A href="http://wiki.splunk.com/Community:More_best_practices_and_processes"&gt;http://wiki.splunk.com/Community:More_best_practices_and_processes&lt;/A&gt;, but I just thought it would be a good idea to do it here too.&lt;/P&gt;

&lt;P&gt;Any help or insight would be greatly appreciated, even a link to another knowledge base would be great.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 18:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/233998#M69541</guid>
      <dc:creator>ianbruton</dc:creator>
      <dc:date>2016-03-04T18:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Are there set guidelines for Splunk search best practices, and are there any other resources on this topic?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/233999#M69542</link>
      <description>&lt;P&gt;Hi @ianbruton&lt;/P&gt;

&lt;P&gt;I'm not sure which Answers posts you've had the chance to check out, but these are some that I've found helpful in learning more about search optimization. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;How to compare fields over multiple sourcetypes without 'join', 'append' or use of subsearches?&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-join-append-or-use-of-subsearches.html"&gt;https://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-join-append-or-use-of-subsearches.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;How do optimizations for field-based searches work?&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/172275/how-do-optimizations-for-field-based-searches-work.html"&gt;https://answers.splunk.com/answers/172275/how-do-optimizations-for-field-based-searches-work.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;What is more efficient for performance: Eventtypes, lookups or calculated fields?&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/149115/what-is-more-efficient-for-performance-eventtypes-lookups-or-calculated-fields.html"&gt;https://answers.splunk.com/answers/149115/what-is-more-efficient-for-performance-eventtypes-lookups-or-calculated-fields.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Why does a simple Splunk search such as index=abc take a long time to complete?&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/225289/why-does-a-simple-splunk-search-such-as-indexabc-t.html"&gt;https://answers.splunk.com/answers/225289/why-does-a-simple-splunk-search-such-as-indexabc-t.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There are some apps in Splunkbase you might want to consider trying out to see how effective your configurations are for optimizing searches and overall health in your environment.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Knowledge Object Explorer&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2871/"&gt;https://splunkbase.splunk.com/app/2871/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Data Curator&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1848/"&gt;https://splunkbase.splunk.com/app/1848/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Some users use this site for some inspiration when crafting up searches to see different and more efficient ways of getting the same results.&lt;BR /&gt;
&lt;A href="http://gosplunk.com/"&gt;http://gosplunk.com/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I'm by no means a search expert, but I'm sure there are many others in the community that can chime in here with their 2 cents. I just spend a lot of time on Answers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 18:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/233999#M69542</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-03-04T18:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Are there set guidelines for Splunk search best practices, and are there any other resources on this topic?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234000#M69543</link>
      <description>&lt;P&gt;Very complex topic ; -) &lt;/P&gt;

&lt;P&gt;It requires a lot of planning otherwise, you end up having a mishmash very quickly. Most software products leave for us the best practices which is really unfortunate. &lt;/P&gt;

&lt;P&gt;One major thing is to come up with a plan for the sourcetypes, which is really important, otherwise we end up with different schemes for this important logical entity.  &lt;/P&gt;

&lt;P&gt;Let me think please about other points...&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 18:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234000#M69543</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-03-04T18:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Are there set guidelines for Splunk search best practices, and are there any other resources on this topic?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234001#M69544</link>
      <description>&lt;P&gt;Yeah I had a feeling that it was going to be a large topic, given that I couldn't think of a way to encapsulate it in a straight forward question. Thank you for your insight though, this is all great information that I can go back to my team with and we can work on creating a plan to move forward with any changes that we need. And if you can think of any other important areas to look out for , please feel free to let me know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 19:09:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234001#M69544</guid>
      <dc:creator>ianbruton</dc:creator>
      <dc:date>2016-03-04T19:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Are there set guidelines for Splunk search best practices, and are there any other resources on this topic?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234002#M69545</link>
      <description>&lt;P&gt;Wow, that's a great amount of info for me to go through! Thanks for taking the time to provide it all to me! I will certainly have a deep dive in there and see if there is anything that we can do better.&lt;/P&gt;

&lt;P&gt;Hopefully some other people will be able to chime in as you say. &lt;/P&gt;

&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 19:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234002#M69545</guid>
      <dc:creator>ianbruton</dc:creator>
      <dc:date>2016-03-04T19:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Are there set guidelines for Splunk search best practices, and are there any other resources on this topic?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234003#M69546</link>
      <description>&lt;P&gt;No problem, I hope you get some good value out it!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 19:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-set-guidelines-for-Splunk-search-best-practices-and/m-p/234003#M69546</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-03-04T19:53:02Z</dc:date>
    </item>
  </channel>
</rss>

