Hello, community
I am trying to identify ways to make this search faster:
index=Win_Logs EventCode IN (528,540,4624) AND user IN (C*,W*,X*)
| dedup user
| timechart span=1w dc(user) as Users
Anything tstats or metasearch, metadata?
Thanks in advance
If your raw data has data like
blablabla...EventCode=528,blablabla
then you can use
index=Win_Logs TERM(EventCode=528) OR
TERM(EventCode=540) OR
TERM(EventCode=4624) AND user IN (C*,W*,X*)
| timechart span=1w dc(user) as Users
You probably don't need the dedup - it's unnecessary as the dc() is doing that anyway.
Also if the raw data has user=BLA... then you could also do TERM(user=C*) ..
Note that for term searches, the raw data MUST have those terms. If you look at the lispy in the search log, you will see different lispy for the TERM() variants and the non TERM variants.
@isoutamothanks for the tip. Unfortunately, I have no datamodels I can use ATM
Regards,