Splunk Search

Splunk SPL best practice

sivaranjiniG
Path Finder

Will a parentheses Surrounded SPL queries make any difference?

For Example:
(index IN (“indexA*”,”indexB*”) source=”sourceA”) and index IN (“indexA*”,”indexB*”) source=”sourceA”

this is a big query want to know if adding  parentheses make any difference in performance wise ? 

0 Karma

adityagupta3010
Engager

Hi there,

To answer your question, the use of paranthesis doesn't affect the performance of your splunk query.

But on the other hand using a "=" instead of the "IN" function will help you; as IN is a function call and splunk processor will always first go to the function definition decode the function then resume the search query.

0 Karma

sivaranjiniG
Path Finder

Hi,
I am not sure how to use multiple indexes without using IN in the query..i dont want to use OR as it takes only one index.i want to use 2 indexes

Can you help?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The IN operator is translated into ORs before the query executes.  So

 

index IN ("indexA*","indexB*")

 

becomes

 

index "indexA*" OR index= "indexB*"

 

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust
Yes, parentheses can make a difference, but in the example given they do not.
Examine the job inspector for each search to confirm.
---
If this reply helps you, Karma would be appreciated.

sivaranjiniG
Path Finder

I checked job Inspect there is difference in seconds..as i said its a big query it may impact performance 

Thanks for suggesting me to check job inspect

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...