Splunk Search

How can I measure the search run time until the first result is returned?

zuckermanori
Engager

I'm benchmarking performance of search queries.

I noticed that although the entire search pipeline takes long to complete, initial results are returned quickly.

how can I measure the query run time until the first result is returned?

currently i'm measuring the entire query run time with 

 

 

history.total_run_time

 

 

but that gives me the total time and I want the time for first result.

Labels (3)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @zuckermanori.

add "| head 1" to your search

Ciao.

Giuseppe

View solution in original post

gcusello
Esteemed Legend

Hi @zuckermanori.

add "| head 1" to your search

Ciao.

Giuseppe

zuckermanori
Engager

thans @gcusello it works, just need to change 

head=1

to 

head 1

please modify your answer and i'll accept it

0 Karma

gcusello
Esteemed Legend

Hi @zuckermanori,

sorry, you're right!

Thank you.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...