Hello
I use a very basic search on a short period like below but I am a little surprised by the quota size used by this search (350 MO for 148000 events between 7h and 13h)
index=tutu sourcetype="toto" type=x earliest=@d+7h latest=@d+19h
| fields sam
| eval sam=lower(s)
| stats dc(s)
So I try to find some tracks for reducing the quota size
Is anybody have an idea please?
What sizes are all other Searchresults usually? Take a look at the Job Activity.