Dashboards & Visualizations

using field in timechart queries


I have a dashboard with many panels. If i used the 'field' command for for the underlying queries, would that help save Splunk resources?

Or does Splunk already know what field to use when it see's 'timechart count by ' and then ignores the rest of the fields???

0 Karma

Ultra Champion

I believe that the timechart command will remove all unnecessary information.

What you could do is to ensure that your question before the timechart runs as efficiently as possible, e.g. specifying the correct index and sourcetype, search only for the time range you're interested in. You could even instruct Splunk to not extract any fields at all (KV_MODE = none in props.conf), and only extract what you need with (an efficient) rex.


Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...