Monitoring Splunk

What is the performance impact of an extensive use of the tstats command?

siva_cg
Path Finder

Hi,

Will there be any impact on Splunk performance if we use tstats very extensively, like more than 10 panels in single dashboard? Thanks in advance.

0 Karma
1 Solution

FrankVl
Ultra Champion

Any search has impact. Tstats is typically less impact-full than a search on raw data, but it still has impact.

If several panels in the dashboard use the same basic data, but present it in different ways, or do some specific statistics on it, it usually pays off to define a base search for your dashboard that gets the basic data that some/all panels need and then, in the panel, you only define the specific additional query to be added to that.

See: https://docs.splunk.com/Splexicon:Basesearch and http://docs.splunk.com/Documentation/Splunk/latest/Viz/Savedsearches#Post-process_searches

View solution in original post

0 Karma

FrankVl
Ultra Champion

Any search has impact. Tstats is typically less impact-full than a search on raw data, but it still has impact.

If several panels in the dashboard use the same basic data, but present it in different ways, or do some specific statistics on it, it usually pays off to define a base search for your dashboard that gets the basic data that some/all panels need and then, in the panel, you only define the specific additional query to be added to that.

See: https://docs.splunk.com/Splexicon:Basesearch and http://docs.splunk.com/Documentation/Splunk/latest/Viz/Savedsearches#Post-process_searches

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...