I have a few searches I want to dashboard that display log events over a week, then another graph for events over a month.
The problem is that there are millions of events weekly and am curious if there is an optimized way I can display log counts w/o a huge search that will take too long.
So really to query the number of items, but not return event specific detail/results.
Thanks!
It would be tough to suggest you something without looking at your queries, but you can utilize summary indexing to pre-calculate the daily/weekly/monthly summary data you want and run your dashboard on summary data. See more details here
http://docs.splunk.com/Documentation/Splunk/6.0.2/Knowledge/Usesummaryindexing