Splunk Search

How to make Splunk stop searching after it finds a certain amount of results?

rockyrush
Explorer

I have tried head 100, but it seems like it does a regular search and then gives me 100 results because it takes the same amount of time as a full search. I am looking for a way not to search 180 million entries when I only need 100 or so results.

0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee
0 Karma

jplumsdaine22
Influencer

What is your search? head should prevent a full search from being executed, unless it comes after a command that requires the data set to come back to the search head

0 Karma

rockyrush
Explorer

Thanks so much! It was after commands which collected all the search terms

0 Karma

rroberts
Splunk Employee
Splunk Employee
0 Karma

rockyrush
Explorer

Not exactly what I was hoping for. I want the latest 100 then I want to to stop searching entirely and just display the results it already has.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...