Splunk Search

Slow child dataset

AKG1_old1
Builder

Hello,

Currently, we are using multiple datamodels for same data (post filters are different). Now we are trying to merge them in single datamodel using child dataset to decrease disk space but appently there is massive performance impact on tstats search queries using child dataset.

In below example, while using child dataset Its almost 300+% increase in search time.

This might be expected as scaning full set of logs. Checking if there is any other way of using tstat query on child dataset to improve performace ?

alt text

Datamodel structure
alt text

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...