I have a search that is taking a few days to run.
Here is the search string:
sourcetype="bcoat_proxysg" | stats dc(c_ip) by date
I send the search to the background and can continue to work but I want to know if there is a way to speed up the this search. Thanks.
Other information:
Running Splunk 4.0.11
PowerEdge R710
Linux 2.6.18-92.el5 CentOS 5.2
load average: 1.39, 1.92, 4.95
MemTotal: 24675796 kB MemFree: 10980696 kB
... View more