I am trying to improve my run time for a large search and i need some help to identify whether eventstats is a Distributable command. From the documentation i know streamstats is Centralized streaming. link:SearchReference/Commandsbytype
What i am trying to achive is not to use those search commands which requires data to be uploaded to Search Heads.
Thanks for your help.
From the doco.
There are a handful of commands that do not fit into these categories. These commands are non-transforming, not distributable, and not streaming: sort, eventstats, some modes of dedup, and some modes of cluster.
eventstats command has the same distribution limitations/characteristics (or not) as
stats does so it should fall into the same category as
streamstats. It is interesting that
eventstats does not appear at all on that page.