Deployment Architecture

Can I search static files for a keyword across all time without a performance penalty?

mjones414
Contributor

I have several hundred files that have been read into Splunk that change very infrequently, but there are times I want to do keyword search across all my file sources without a time context. Is there any way to do this without the all time performance penalty?

0 Karma

rjthibod
Champion

If you are looking for a very specific word or continuous set of characters, then TERM() is what you want to use. That is the fastest way to find instances of a specific word.

TERM() is used in the initial search segment of your query, like this: index=... TERM(<keyword>) | ....

rjthibod
Champion
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...