Splunk Search

How to stop searching when first result was found in each index in multisearch

Raymond2T
Path Finder

Hello 

I find it difficult to stop the search when I got first result in multisearch.

I tried |head 1  but it can't be implemented in multisearch 

Is there anyway to stop it to enhance my search efficiency?

Because I got over 10 indexes which has over 10 million entires in each index to search.
|multisearch
[index = A |search ....]
[index = B |search ....]
[index = C |search ....]
[index = D |search ....]

....


Thank you so much.

Labels (3)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Raymond2T,

If your subsearches does not return to many events you can use append like below.

Please try below;

index=A memberID = 1234567 |eval ID = memberID | head 1
| append [search index=B ID= 1234567 | head 1 ]
| append [search index=C membernum=1234567|eval ID =membernum | head 1]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

scelikok
SplunkTrust
SplunkTrust

Hi @Raymond2T,

Are these sub searches totally different? If you can share your searches (anonymized) we can find another way to achieve your goal.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

Raymond2T
Path Finder

it is different because there are different indexes with different field names.

For example

|multisearch

[ index=A |search memberID = 1234567 |eval ID = memberID]

[index=B |search ID= 1234567 ]

[index=C|search membernum=1234567|eval ID =membernum]


I would like to stop the subsearch of index C once first result was found as it has a huge event size, e.g. over 10GB.

I don't want it to search all 10GB data that waste a lot of time and it is definitely not a good performance.

Thank you

0 Karma

starcher
Influencer

There is no such mechanism. 

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...