|
best tips for speeding up searches? |
|
One could write a Novel on this, but I'll focus on reporting type searches...
- thanks! . .
(11 May '11, 08:54)
transamrit
|
|
-Turn field discovery off if you haven't used any additional fields perhaps.... -select a smaller time range then "All Time" -Perhaps your search is too generic? Try narrowing the search down to more specific data that you are looking for.... Thinking of other ways......hmmm.... |
|
It's going to sound obvious, but, "be as specific as you can be" in your search. I've got nearly 500,000,000 events in my Splunk at the moment and I definitely get the best results for speed when I use as many of the indexed fields as possible in my query. Host, source, sourcetype, time range (important one!), index name, and so on. As others have pointed out, if you can disable field discovery, that will help a lot as well. |