Splunk Search

How to make Splunk stop searching after it finds a certain amount of results?

rockyrush
Explorer

I have tried head 100, but it seems like it does a regular search and then gives me 100 results because it takes the same amount of time as a full search. I am looking for a way not to search 180 million entries when I only need 100 or so results.

0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee
0 Karma

jplumsdaine22
Influencer

What is your search? head should prevent a full search from being executed, unless it comes after a command that requires the data set to come back to the search head

0 Karma

rockyrush
Explorer

Thanks so much! It was after commands which collected all the search terms

0 Karma

rroberts
Splunk Employee
Splunk Employee
0 Karma

rockyrush
Explorer

Not exactly what I was hoping for. I want the latest 100 then I want to to stop searching entirely and just display the results it already has.

Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...