Splunk Search

How to make Splunk stop searching after it finds a certain amount of results?

Explorer

I have tried head 100, but it seems like it does a regular search and then gives me 100 results because it takes the same amount of time as a full search. I am looking for a way not to search 180 million entries when I only need 100 or so results.

0 Karma
1 Solution

Splunk Employee
Splunk Employee
0 Karma

Influencer

What is your search? head should prevent a full search from being executed, unless it comes after a command that requires the data set to come back to the search head

0 Karma

Explorer

Thanks so much! It was after commands which collected all the search terms

0 Karma

Splunk Employee
Splunk Employee
0 Karma

Explorer

Not exactly what I was hoping for. I want the latest 100 then I want to to stop searching entirely and just display the results it already has.