Splunk Search

Dedup performance 1 field vs multiple fields vs concatenated field

wfskmoney
Path Finder

Which one would be faster or better in general:

  1. | dedup fieldA fieldB --> I would assume that Splunk does a concatenation in the background
  2. | eval fieldAB = fieldA.fieldB | dedup fieldAB
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi wfskmoney,
I didn't found great differences between the methods (a few hundredths of a second):
scan ot 700,000 events in 8.568 s. in the first case and 8.529 s. in thesecond case.

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi wfskmoney,
I didn't found great differences between the methods (a few hundredths of a second):
scan ot 700,000 events in 8.568 s. in the first case and 8.529 s. in thesecond case.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...