Splunk Search

Most efficient: alot of smaller searches or one large one

skippylou
Communicator

Trying to find out what is most efficient in this scenario resource/time wise.

We want to do a search across the last 90 days that looks for sshd and matching a user, to look for logins.

Is it better to loop over a user list inputting a search for each user separately as 'earliest=-90d sshd user=$var_user' one at a time or to do one search with all the users OR'ed like so 'earliest=-90d sshd (user=$var_user OR user=$var_user1 OR....)'?

This is in the context of the user list being hundreds of users long. So are hundreds of stacked up long-length single-term searches better than lots and lots of ORs across the same time range in a single search.

Thoughts?

Scott

Tags (1)
0 Karma

ziegfried
Influencer

The single search is most probably the most efficient one.

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...