Splunk Search

Splunk SPL best practice

sivaranjiniG
Communicator

Will a parentheses Surrounded SPL queries make any difference?

For Example:
(index IN (“indexA*”,”indexB*”) source=”sourceA”) and index IN (“indexA*”,”indexB*”) source=”sourceA”

this is a big query want to know if adding  parentheses make any difference in performance wise ? 

0 Karma

adityagupta3010
Engager

Hi there,

To answer your question, the use of paranthesis doesn't affect the performance of your splunk query.

But on the other hand using a "=" instead of the "IN" function will help you; as IN is a function call and splunk processor will always first go to the function definition decode the function then resume the search query.

0 Karma

sivaranjiniG
Communicator

Hi,
I am not sure how to use multiple indexes without using IN in the query..i dont want to use OR as it takes only one index.i want to use 2 indexes

Can you help?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The IN operator is translated into ORs before the query executes.  So

 

index IN ("indexA*","indexB*")

 

becomes

 

index "indexA*" OR index= "indexB*"

 

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust
Yes, parentheses can make a difference, but in the example given they do not.
Examine the job inspector for each search to confirm.
---
If this reply helps you, Karma would be appreciated.

sivaranjiniG
Communicator

I checked job Inspect there is difference in seconds..as i said its a big query it may impact performance 

Thanks for suggesting me to check job inspect

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...