Splunk Search

does drilldown option contribute in search optimization

mdmaala
Communicator

does drilldown option help in optimizing the search? because when I try to place all the panels in one dashboard, the search is getting slower, thus, causing delays in the real time visualization.

Tags (1)
0 Karma

niketn
Legend

@mdmaala, search optimization depends on several conditions and community would be able to assist you better if you can provide the searches running in your dashboard and also how you plan to use drilldown.

If your drilldown filters results being pulled back from index, it would help as there will be less event to search. Refer to Splunk documentation on Search Optimization.

By Real-Time visualization do you mean searches running on Real-Time time window? If so do understand the limitation of Real-Time Searches

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

mdmaala
Communicator

thank you so much @niketnilay ! I will look on these. by real time visualization what I mean is that once the data updates where splunk indexes its file from, the dashboard will automatically update.

0 Karma

mdmaala
Communicator

thank you so much @niketnilay I will look on these. By real time visualization, what I mean is once the log file updates, the dashboard will also update. In my case, one the light changes from one state to another, the dashboard should immediately display the total duration of the previous state. For now, I will try summary indexing along with doing a drilldown to optimize the searching.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...