Splunk Search

Search optimization

troy44112
Explorer

.

Labels (1)
0 Karma

bowesmana
Champion

Does it need optimising?

You're trying to find src values with more than 300 events in a 45s period. 

What is the context? Is it part of a dashboard and what is the wider time period. Optimisations can be done using summary indexes, where you calculate these counts using a scheduled search and then your query can then search the summary which will only contain the results of that query as opposed to the raw data.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.