We have an external database. The database is emptied & re-populate daily. The content is 80% similiar as the previous database. There is no uniq index field saying the 1st 80% are old data & the last 20% of data are new incoming data. The total records are 6 million. We use Splunk DB Connect to bring in the data. Over time, the total records become 50 million. 8x more data. The simple search like index="XXX" is taking longer than dbxquery and saved search. We observed using stats can improve the stat command for index="XXX". But, we still need to further improve the query turnaround time. Hence we are thinking of substituting the index="XXX" with dbxquery or saved_search to further boost the stats query. We tried with 3 syntaxes attached. Observed "no result found" when substituting index="XXX" with dbxquery & saved_searched. Can we learn the right syntax to put tstats & dbxquery or saved_searched together, please?
... View more