Hi, need some expert help tuning a search query focused only on ITSI users per week. I have the following query but it is running really slow.
index="internal" host= app=itsi NOT user="splunk-system-user"| timechart span=1d count as countuser by user usenull=f
Any suggestions are welcomed.
Do you have a more specific goal you are trying to achieve aside from counting events from the itsi app by user? That will help tailor the search requirements.
index=_internal host=<insert-your-ITSI-host(s)> source="/opt/splunk/var/log/splunk/splunkd_ui_access.log" uri=*SA-ITOA/itoa_interface* |timechart span=1d dc(user) as users