Hi,
I've got ~15.000 events where FieldA exists (in total there are 20.000.000 events). I want to filter out these events and I'm wondering about the performance of different approaches.
Why i...
Hi
I am running a heavy forwarder with HEC and it is sending data to 3 indexers. I am starting to read about ways to optimise this configuration, but I am not sure if I have all the s...
..." only returns about 300 results, but the subsearch is searching across millions of users accounts. If I removed the sub search, the outer search only takes a few seconds to complete.
Does a...
...isplay the dashboard. What constitutes a search: a data base search? or does the post search also count?
2) I did some rough counts, If I merge the 5 summary-indexes into one, there will be about 3...
I would like to use a lookup into an external database to add fields to my events, but need some advice about performance and caching of expensive lookups.
For example, say I have a log of o...
F.ex. when using NLog file target: https://github.com/NLog/NLog/wiki/File-target What's the optimal performance way for creating log files for the Forwarder? One record per file (t...
...o keep clean with time and dashboards add, not satisfying.
2. Summary indexing
Summary indexing as far as i understood the way Splunk works is one of logical way to achieve optimization.
U...
...sers BY server_id
I'm thinking about how to optimize the performance of this dashboard.
1. Report Acceleration
Accelerate this base search (the output will be at least >3.000.000 r...
I have a dashboard that has over 30 panels - they all have the same basic search query so I decided to use the new search optimization of Splunk 6.2. Here is what I did - I defined a global search a...
...nown IPs from the logdata. However the searches seem to take a long time, and I'm not sure if its due to my non-optimized search or that its just too much logdata.
My goal was to search through the l...