I have found this entry in one of the blogs (non-Splunk). Do you think this statement is correct?
The following are search terms we will be generating based on a 10,000,000 line file.
· Very Dense Search, 1 out of 100 lines, 100,000 occurrences.
· Dense Search, 1 out of 1000 lines, 10,000 occurrences.
· Extremely Rare Search, 1 out of 100,000,000 lines
· Sparse Search, 1 out of 10,000,000 lines, 1 occurrence.
· Rare Search 1 out of 1,000,000 lines, 10 occurrences.
while there are some good sources out there, I would stick to the docs http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowsearchtypesaffectSplunkEnterpriseperfo... in this case.
Hope this helps ...
I did see this link.. but I am confused with Super-parse and rare search. If I have 10 million lines, what will be the occurrences?