Splunk Dev

Is the where clause a streaming or non-streaming command.

tjago11
Communicator

Trying to optimize some queries and can't find a definitive answer on where the where clause runs. It looks like it is executing on the indexers because filtering the data before the stats command seems faster, but I'd like a straightforward answer. Thanks.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

where is a streaming command.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

where is a streaming command.

---
If this reply helps you, Karma would be appreciated.

somesoni2
Revered Legend
0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...