<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297622#M89808</link>
    <description>&lt;P&gt;The field extractions are defined in the props.conf and transforms.conf files. if you are in smart or verbose mode splunk will do all extractions that apply to your data (e.g. that apply to the sourcetypes you searching). You can build your own props/transforms to extract only the fields you need. &lt;BR /&gt;
Nevertheless can you elaborate on the performance problem you are facing?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 22:59:30 GMT</pubDate>
    <dc:creator>diogofgm</dc:creator>
    <dc:date>2017-10-13T22:59:30Z</dc:date>
    <item>
      <title>Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297621#M89807</link>
      <description>&lt;P&gt;As far as I know, fields- does not improve performance, and I'm looking for a better option. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 22:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297621#M89807</guid>
      <dc:creator>dannyzen</dc:creator>
      <dc:date>2017-10-13T22:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297622#M89808</link>
      <description>&lt;P&gt;The field extractions are defined in the props.conf and transforms.conf files. if you are in smart or verbose mode splunk will do all extractions that apply to your data (e.g. that apply to the sourcetypes you searching). You can build your own props/transforms to extract only the fields you need. &lt;BR /&gt;
Nevertheless can you elaborate on the performance problem you are facing?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 22:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297622#M89808</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2017-10-13T22:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297623#M89809</link>
      <description>&lt;P&gt;For ad-hoc searches, make sure to set the &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Search/Changethesearchmode"&gt;search mode&lt;/A&gt; to 'Fast' in the UI and Splunk will skip field extraction as much as possible. For saved  searches reports, 'Smart' mode is the default.&lt;/P&gt;

&lt;P&gt;You can observe the performance difference in job inspector by looking for the &lt;STRONG&gt;command.search.kv&lt;/STRONG&gt; metric.&lt;/P&gt;

&lt;P&gt;There are many more aspects of SPL and your Splunk infrastructure itself that affect Splunk performance, so if you have a specific performance issue, please post your search and the contents of the job inspector window if you are looking for more detailed help.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 23:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297623#M89809</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-13T23:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297624#M89810</link>
      <description>&lt;P&gt;Thank you, for an ad-hoc search I just want an alternative to fields- if there is one?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 23:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297624#M89810</guid>
      <dc:creator>dannyzen</dc:creator>
      <dc:date>2017-10-13T23:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297625#M89811</link>
      <description>&lt;P&gt;Not to my knowledge, outside of setting the search mode.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 23:29:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297625#M89811</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-13T23:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297626#M89812</link>
      <description>&lt;P&gt;What is the purpose / what are you trying to achieve here?&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 02:09:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297626#M89812</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-14T02:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Which command or stanza can be used to decide which fields are extracted at search time to improve performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297627#M89813</link>
      <description>&lt;P&gt;Improve performance on &lt;STRONG&gt;&lt;EM&gt;what&lt;/EM&gt;&lt;/STRONG&gt;?&lt;/P&gt;

&lt;P&gt;If you put &lt;CODE&gt;fields&lt;/CODE&gt; at the very top of your query, it saves a lot of extraction costs.  But, generally, you want to use the positive version - tell the system the list of fields that you actually DO need, rather than the ones you don't. &lt;/P&gt;

&lt;P&gt;Lower down, &lt;CODE&gt;| fields -&lt;/CODE&gt; will reduce the overhead marginally, by reducing what gets passed through the following pipeline.  This can be a major reduction if everything above it is a streaming command, so you save yourself from passing data from the indexers to the search head.  &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;There are a large number of optimization techniques that are data-dependent.  In my experience, most effective refactoring efforts consist of converting the query to a different search model that is more appropriate to the data mix.&lt;/P&gt;

&lt;P&gt;If you post the individual queries as separate questions - "how can I optimize this search?"  - then we can help you figure out what would work for each one.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 21:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-command-or-stanza-can-be-used-to-decide-which-fields-are/m-p/297627#M89813</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-10-14T21:12:50Z</dc:date>
    </item>
  </channel>
</rss>

