Splunk Search

Optimizing a search in splunk

gimbil
Explorer

Hi,

I am trying to do a search which basically generates measures based on the value of a field such as X:

search logs|…..| timechart count(eval(X="1" OR X="2")) AS "A",  count(eval(X="1")) AS "B",  count(eval(X="2")) AS "C",  count(eval(X="3")) AS "D", count(eval(X="4" OR X="5" OR X="6")) as "E" span=1d

however, generating results takes for ever. If I remove some of the counts (like the one to generate "E") it becomes much faster. Is there anyway to better optimize this search?

Thanks

0 Karma

ShaneNewman
Motivator

The answer given by somesoni2 will make it more efficient. The other option is to create a summary index, then search the summary index.

mdmaala
Communicator

how to create a summary index and how will I call it in the search bar?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust
0 Karma

somesoni2
Revered Legend

Try following

search logs|…..| eval countField=case(X="1" OR X="2","A",X="1","B",X="2","C",X="3","D",X="4" OR X="5" OR X="6","E",1=1,"E") | timechart count(eval(countfield="A"))AS "A", count(countfield="B") AS "B", count(eval(countfield="C")) AS "C", count(eval(countfield="D")) AS "D", count(eval(countfield="E")) as "E" span=1d

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...