Splunk Search

How to save the system resources of realtime search?

laiyongmao
Path Finder

If I want to run for realtime search, but my machine does not support, how to save the resource of the system?

Tags (1)
0 Karma
1 Solution

jtrucks
Splunk Employee
Splunk Employee

The closest you can get is to schedule a search every minute that looks at earliest=-1m@m latest=-0m@m to iterate over the previous minute. Worst case your results are about a minute lagged from the events.

--
Jesse Trucks
Minister of Magic

View solution in original post

0 Karma

jtrucks
Splunk Employee
Splunk Employee

The closest you can get is to schedule a search every minute that looks at earliest=-1m@m latest=-0m@m to iterate over the previous minute. Worst case your results are about a minute lagged from the events.

--
Jesse Trucks
Minister of Magic
0 Karma

laiyongmao
Path Finder

Thank you jtrucks ! because we require data accuracy and high safety, all I want to know Splunk high availability is how to achieve, what is the internal mechanism, how in the optimal conditions, the realization of these?

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...