Monitoring Splunk

Which is more efficient - filldown or streamstats

simpkins1958
Contributor
... | sort _time | filldown l_lat l_lon by UID | table _time UID w_tbys w_tbyr l_lat l_lon 

or

... | sort _time | streamstats last(l_lat) as lastLat last(l_lon) as lastLon by UID | table _time UID w_tbys w_tbyr l_lat lastLat l_lon lastLon
0 Karma

RR5027153
New Member

filldown does not support "by" argument so if you need "by" arguments , filldown is not an right option for you . check here https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Filldown

0 Karma

MuS
SplunkTrust
SplunkTrust

Run both searches on your system searching your events over the same time range and check the job inspector for each search and you will get the answer which one will perform best for you in your environment.

woodcock
Esteemed Legend

What @MuS said (he beat me to it).

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...