Splunk Search

Why is the search with NOT take less time compared to search using IN?

Wonder_women
Loves-to-Learn

Hello Everyone, I have two queries  to exclude events one using NOT and other one using IN, both the queries returning same results but the query using NOT command takes less time.

My question is it should be other way around, why NOT is take less time to execute.    

 

Wonder_women_1-1662372107763.png

Time taken by Splunk using IN query

Wonder_women_2-1662372203944.png

Time taken by Splunk using NOT query

 

 

index = "some_index" sourcetype="some_sourec_type" app_code=XXXX a_status IN (0,1,40) AND b_status IN (2,1,10,20)

index = "some_index" sourcetype="some_sourec_type" app_code=XXXX NOT a_status IN (0, -1, -2, -5) NOT b_status IN (-1, -6, -5, null)


Labels (1)
0 Karma

Wonder_women
Loves-to-Learn

Hi @gcusello, 0 is in both the condition.

I executed the query yesterday and then today, it shows the same behavior.  

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Wonder_women,

zero in both conditions, means that the two searches have different results,

probably the zero condition matches many events and so the NOT conditions excludes more events, so in the result you have much less events so the results visualization is faster.

Try to use zero only in one of the searches.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Wonder_women,

in general a NOT condition is always slower than an IN condition, so it's very strange your behavior.

Only two questions:

  • the condition a_status=0 is in both the searches, it's a copy/past error, or it's present in bothe the searches?
  • di you tried to execute the two searches in different times? in other words does the condition search_IN slower happen all the time or it's temporary?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...