Splunk Search

What is the difference between the metasearch and tstats commands?

muebel
SplunkTrust
SplunkTrust

I've been using tstats for most of the use cases that metasearch covers, and so I'm interested in what metasearch can do that tstats can't. From my reading of the documentation, it seems that metasearch is a subset of the capability of tstats (i.e. tstats can search over accelerated datamodels).

Am I missing anything?

1 Solution

cpride_splunk
Splunk Employee
Splunk Employee

The two are operators on a different level.
tstats -- all about stats. It does this based on fields encoded in the tsidx files. You can use this to result in rudimentary searches by just reducing the question you are asking to stats. It is however a reporting level command and is designed to result in statistics.

metasearch -- this actually uses the base search operator in a special mode where we do not read from the journal.gz. So this is an event based command. We actually treat things as events. Due to the fact that we are not reading form the journal.gz this can only use information that exists in the tsidx files.

Thus they are both tsidx based, however one is based on events and the other is based on statistics as a base object type.

View solution in original post

cpride_splunk
Splunk Employee
Splunk Employee

The two are operators on a different level.
tstats -- all about stats. It does this based on fields encoded in the tsidx files. You can use this to result in rudimentary searches by just reducing the question you are asking to stats. It is however a reporting level command and is designed to result in statistics.

metasearch -- this actually uses the base search operator in a special mode where we do not read from the journal.gz. So this is an event based command. We actually treat things as events. Due to the fact that we are not reading form the journal.gz this can only use information that exists in the tsidx files.

Thus they are both tsidx based, however one is based on events and the other is based on statistics as a base object type.

martin_mueller
SplunkTrust
SplunkTrust

Adding to that, metasearch is often around two orders of magnitude slower than tstats.

This takes 0.23 seconds on my PC: | tstats count where index=_internal by source
This takes 29.4 seconds: | metasearch index=_internal | stats count by source

One thing metasearch can do that tstats can't: Discovery of indexed fields:

| metasearch index=_internal | fieldsummary

tstats forces you to stats your data, while not allowing something like values(*) to peek into unknown data.

muebel
SplunkTrust
SplunkTrust

thanks Martin! That fieldsummary bit is a good point.

0 Karma

somesoni2
Revered Legend

No.. that's pretty much it. metasearch was older way to query tsidx data (metadata fields). The tstats command is advanced/improved form of metasearch.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...