<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Make search faster in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239707#M71222</link>
    <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=test sourcetype=Perfmon:* | lookup khi_threshold_id counter AS counter object AS object OUTPUTNEW description AS description id AS id threshold AS threshold  | search id="1"
| bucket span=5m _time | stats avg(Value) as Value values(threshold) as threshold by _time host
| appendpipe [stats values(threshold) as Value by _time | eval host="threshold"]
| timechart avg(Value) as Value by host  | table _time * threshold
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 10 Mar 2016 17:21:47 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-03-10T17:21:47Z</dc:date>
    <item>
      <title>Make search faster</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239705#M71220</link>
      <description>&lt;P&gt;Hello &lt;/P&gt;

&lt;P&gt;I have the following search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=test sourcetype=Perfmon:* | lookup khi_threshold_id counter AS counter object AS object OUTPUTNEW description AS description id AS id threshold AS threshold  | search id="1" |  timechart avg(Value) as Value by host |  appendcols  [search index=test  sourcetype=Perfmon:* | lookup khi_threshold_id counter AS counter object AS object OUTPUTNEW description AS description id AS id threshold AS threshold | search id="1"  |  bucket _time span=5min |  timechart values(threshold) as "threshold"]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The problem is, that the search takes too much time.&lt;BR /&gt;
Is there a way to make the search faster?&lt;/P&gt;

&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 10:56:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239705#M71220</guid>
      <dc:creator>tgdvopab</dc:creator>
      <dc:date>2016-03-10T10:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Make search faster</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239706#M71221</link>
      <description>&lt;P&gt;Making the lookup automatic would allow you to pull the limitation "search id="1"" into the base search which should speed things up.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 17:14:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239706#M71221</guid>
      <dc:creator>JMichaelis</dc:creator>
      <dc:date>2016-03-10T17:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Make search faster</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239707#M71222</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=test sourcetype=Perfmon:* | lookup khi_threshold_id counter AS counter object AS object OUTPUTNEW description AS description id AS id threshold AS threshold  | search id="1"
| bucket span=5m _time | stats avg(Value) as Value values(threshold) as threshold by _time host
| appendpipe [stats values(threshold) as Value by _time | eval host="threshold"]
| timechart avg(Value) as Value by host  | table _time * threshold
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 10 Mar 2016 17:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239707#M71222</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-03-10T17:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Make search faster</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239708#M71223</link>
      <description>&lt;P&gt;Thanks a lot for your solution! The search ist very fast now.&lt;BR /&gt;
Could you explain me, what "appendpipe" and at the end "table" does?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 11:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239708#M71223</guid>
      <dc:creator>tgdvopab</dc:creator>
      <dc:date>2016-03-11T11:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Make search faster</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239709#M71224</link>
      <description>&lt;P&gt;Since, your first query aggregates based on host and time but second query does only by time, the query before appendpipe is doing summary of both value and threshold (I assume threshold is constant for a host) and appendpipe generate a summary just of time (no host). The eval inside appendpipe subsearch ensure threshold be added as host so that a column/series can be generated by the subsequent timechart.&lt;/P&gt;

&lt;P&gt;The last table just does the column ordering _time, "all hosts", threshold&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 15:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Make-search-faster/m-p/239709#M71224</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-03-11T15:28:10Z</dc:date>
    </item>
  </channel>
</rss>

