Splunk Search

How to stop searching when first result was found in each index in multisearch

Raymond2T
Path Finder

Hello 

I find it difficult to stop the search when I got first result in multisearch.

I tried |head 1  but it can't be implemented in multisearch 

Is there anyway to stop it to enhance my search efficiency?

Because I got over 10 indexes which has over 10 million entires in each index to search.
|multisearch
[index = A |search ....]
[index = B |search ....]
[index = C |search ....]
[index = D |search ....]

....


Thank you so much.

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Raymond2T,

If your subsearches does not return to many events you can use append like below.

Please try below;

index=A memberID = 1234567 |eval ID = memberID | head 1
| append [search index=B ID= 1234567 | head 1 ]
| append [search index=C membernum=1234567|eval ID =membernum | head 1]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

scelikok
SplunkTrust
SplunkTrust

Hi @Raymond2T,

Are these sub searches totally different? If you can share your searches (anonymized) we can find another way to achieve your goal.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

Raymond2T
Path Finder

it is different because there are different indexes with different field names.

For example

|multisearch

[ index=A |search memberID = 1234567 |eval ID = memberID]

[index=B |search ID= 1234567 ]

[index=C|search membernum=1234567|eval ID =membernum]


I would like to stop the subsearch of index C once first result was found as it has a huge event size, e.g. over 10GB.

I don't want it to search all 10GB data that waste a lot of time and it is definitely not a good performance.

Thank you

0 Karma

starcher
Influencer

There is no such mechanism. 

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...