Splunk Search

Finding a search is dense or sparse or rare search by looking into search dispatch directory.

sibanandapani1
Explorer

We have few searches. How to find whether search is a rare search, or Dense or Sparse search.

Was there anywhere log for this thing. Please help me.

Tags (1)
0 Karma

jluste
Path Finder

Taken from Slide 26 of the Search Optimization in 500 Easy Steps presentation given at .conf2014 by Julian Harty.

How can I determine if my search is Dense or Sparse?
Use Job Inspector…

scanCount = The number of events that are scanned or read off disk.
eventCount = Number of events that are returned to base search

• For dense searches scanCount ~= eventCount.
• For sparse searches, scanCount >> eventCount.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...