Splunk Search

Most efficient: alot of smaller searches or one large one

skippylou
Communicator

Trying to find out what is most efficient in this scenario resource/time wise.

We want to do a search across the last 90 days that looks for sshd and matching a user, to look for logins.

Is it better to loop over a user list inputting a search for each user separately as 'earliest=-90d sshd user=$var_user' one at a time or to do one search with all the users OR'ed like so 'earliest=-90d sshd (user=$var_user OR user=$var_user1 OR....)'?

This is in the context of the user list being hundreds of users long. So are hundreds of stacked up long-length single-term searches better than lots and lots of ORs across the same time range in a single search.

Thoughts?

Scott

Tags (1)
0 Karma

ziegfried
Influencer

The single search is most probably the most efficient one.

Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...