<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic index'd Time extractions in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/index-d-Time-extractions/m-p/244612#M72874</link>
    <description>&lt;P&gt;Hey guys, &lt;/P&gt;

&lt;P&gt;So I am looking at index'd time extraction as a possibly helping with my search time field extraction troubles. Any idea how I might measure this? &lt;/P&gt;

&lt;P&gt;Background: &lt;BR /&gt;
We process about ~1billion events a day in our Splunk instance. The first 4 characters of hostnames on our servers is our datacenterID. The field extraction is therefore running.. 10's of millions of times in any search. &lt;BR /&gt;
1) This isn't going to change&lt;BR /&gt;
2) We're using this field in hundreds of searches already&lt;/P&gt;

&lt;P&gt;How would I know if this would help or not?&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2016 03:27:02 GMT</pubDate>
    <dc:creator>daniel333</dc:creator>
    <dc:date>2016-03-10T03:27:02Z</dc:date>
    <item>
      <title>index'd Time extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/index-d-Time-extractions/m-p/244612#M72874</link>
      <description>&lt;P&gt;Hey guys, &lt;/P&gt;

&lt;P&gt;So I am looking at index'd time extraction as a possibly helping with my search time field extraction troubles. Any idea how I might measure this? &lt;/P&gt;

&lt;P&gt;Background: &lt;BR /&gt;
We process about ~1billion events a day in our Splunk instance. The first 4 characters of hostnames on our servers is our datacenterID. The field extraction is therefore running.. 10's of millions of times in any search. &lt;BR /&gt;
1) This isn't going to change&lt;BR /&gt;
2) We're using this field in hundreds of searches already&lt;/P&gt;

&lt;P&gt;How would I know if this would help or not?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 03:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/index-d-Time-extractions/m-p/244612#M72874</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2016-03-10T03:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: index'd Time extractions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/index-d-Time-extractions/m-p/244613#M72875</link>
      <description>&lt;P&gt;I am not an expert in this, but hopefully this will answer will pop to the front of the queue and someone who is can correct me if I'm wrong.&lt;/P&gt;

&lt;P&gt;It seems like what you are describing would be a good thing - generally it's unrecommended to build index time extractions, but there are definitely times it's useful and good.  &lt;/P&gt;

&lt;P&gt;This will increase license.  4 characters each, a billion a day; that's 4 billion characters you will be adding to your license amount.  Probably not a big issue in your environment because I'd guess the rest of the events are far larger.&lt;/P&gt;

&lt;P&gt;That being said, I don't see too much downside to just trying it except effort and time.  I'd find good "measurements" before trying, though, because you'll definitely want to measure the impact.&lt;/P&gt;

&lt;P&gt;Another thought - are these all in the same index?  how many data centers?  Could you rework it to move each DC to a different index, then you'd change your "DC" part of your searches to &lt;CODE&gt;index=dc04&lt;/CODE&gt; or &lt;CODE&gt;index=dc04 OR index=dc55&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 12:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/index-d-Time-extractions/m-p/244613#M72875</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-03-11T12:54:38Z</dc:date>
    </item>
  </channel>
</rss>

