Splunk Search

Does sequence matter in search?

Pathik
Path Finder

Does sequence matter in search? from below 2 queries, which is recommended or both will perform with same performance?

Query1:

index=myindex AND "mystring" AND host=myprodhost*

Query2:

index=myindex AND host=myprodhost* AND "mystring" 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Pathik,

it's absolutely the same!

and you don't need to use the "AND" operator.

Ciao.

Giuseppe

View solution in original post

0 Karma

Pathik
Path Finder

@gcusello  thanks, so splunk would find best optimum fields to search first and then proceed with others... thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Pathik,

it's absolutely the same!

and you don't need to use the "AND" operator.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Pathik,

the search algorithm of Splunk choose the most efficient combination of fields.

Ciao and good splunking.

Giuseppe

P.S. Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...