when you use the collect command, you save the search results in a summary index that's and index with asll indexed fields.
So you have to create your search ending with the table command and store results in a summary index.
Then you can search on the summary index that's more performant.
see the documentation at https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Collect
see also mcollect and tscollect.
Hi @gcusello ,
Thank you very much for your response.
Already we have tried the same thing.
Here Problem is we are able to store the table results to summary index using collect.
But we are unable perform tstats on these summary index fileds.
Can you please help us in this.