The Community of Splunk Enthusiast

This is a fan site and not an official Splunk site

Menu
  • Home
  • BSides Splunk
    • Current Schedule
    • Current Talks
    • Archives
  • Call For Papers
    • Presentation Recording Tips

Leveraging SearchNow in Summary index to boost query performance

Description:
As a general practice to get the latest data from Summary index, the developer will fire a command to fetch the latest of each field (by latest command. Eg. latest(field1), latest(field2), etc.).
This a performance killer and the approach can be changed to leverage the already available field “”SearchNow”” in the query.

Speaker:
Gauri Bansode

Day and Time:
 

  • Home
  • BSides Splunk
    • Current Schedule
    • Current Talks
    • Archives
  • Call For Papers
    • Presentation Recording Tips

© 2020 Splunk Community. All Rights Reserved.