Hi all,
I have a couple applications that each of them have six or seven dashboards, with multiple users accesing simultaneously.
All of the dashboards are similar in structure, consisting of a good number of complex searches. I have tried to use saved searches where possible, since the load time of the dashboards is far from acceptable, however, I do not know how to apply this technique to the vast majority of them, since most of the searches are parameterized with tokens that receive a value when invoked from a drilldown from another dashboard. Is there a way to accelerate these searches? Is it possible to save a parameterized search? If not, is there another mechanism to improve the performance?
Thanks in advance.
There are a couple of things you could try.
http://docs.splunk.com/Documentation/Splunk/6.3.3/Knowledge/Usesummaryindexing
http://docs.splunk.com/Documentation/Splunk/6.3.3/Knowledge/Acceleratedatamodels
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Loadjob
http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/Savedsearches
Which option you choose depends on what your searches look like, how much work you want Splunk to perform in the background, and how much control you want over the acceleration.
There are a couple of things you could try.
http://docs.splunk.com/Documentation/Splunk/6.3.3/Knowledge/Usesummaryindexing
http://docs.splunk.com/Documentation/Splunk/6.3.3/Knowledge/Acceleratedatamodels
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Loadjob
http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/Savedsearches
Which option you choose depends on what your searches look like, how much work you want Splunk to perform in the background, and how much control you want over the acceleration.