Hello,
I have events that contain fields ID and parentID. By using those fields I would like to find all the events with selected ID and all the parents in hierarchy, so also parent of the parent etc. I know how to deal with the problem with transaction, however it takes a lot of time to finish, if the index has much data.
Is there any other way to deal with the problem?
try using streamstats. I often avoid transaction with streamstats. you can't have a 'startswith'/'endswith', but there are helpful arguments. I've brought in the documentation.
http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Streamstats