Splunk Search

How to make Splunk stop searching after it finds a certain amount of results?

rockyrush
Explorer

I have tried head 100, but it seems like it does a regular search and then gives me 100 results because it takes the same amount of time as a full search. I am looking for a way not to search 180 million entries when I only need 100 or so results.

0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee
0 Karma

jplumsdaine22
Influencer

What is your search? head should prevent a full search from being executed, unless it comes after a command that requires the data set to come back to the search head

0 Karma

rockyrush
Explorer

Thanks so much! It was after commands which collected all the search terms

0 Karma

rroberts
Splunk Employee
Splunk Employee
0 Karma

rockyrush
Explorer

Not exactly what I was hoping for. I want the latest 100 then I want to to stop searching entirely and just display the results it already has.

Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...