Splunk Search

does drilldown option contribute in search optimization

mdmaala
Communicator

does drilldown option help in optimizing the search? because when I try to place all the panels in one dashboard, the search is getting slower, thus, causing delays in the real time visualization.

Tags (1)
0 Karma

niketn
Legend

@mdmaala, search optimization depends on several conditions and community would be able to assist you better if you can provide the searches running in your dashboard and also how you plan to use drilldown.

If your drilldown filters results being pulled back from index, it would help as there will be less event to search. Refer to Splunk documentation on Search Optimization.

By Real-Time visualization do you mean searches running on Real-Time time window? If so do understand the limitation of Real-Time Searches

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

mdmaala
Communicator

thank you so much @niketnilay ! I will look on these. by real time visualization what I mean is that once the data updates where splunk indexes its file from, the dashboard will automatically update.

0 Karma

mdmaala
Communicator

thank you so much @niketnilay I will look on these. By real time visualization, what I mean is once the log file updates, the dashboard will also update. In my case, one the light changes from one state to another, the dashboard should immediately display the total duration of the previous state. For now, I will try summary indexing along with doing a drilldown to optimize the searching.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...