Has anyone come across any good references or resource material explaining lispy
? This is visible from the search inspector and can give you some good insights into how Splunk is executing your core search, but I've not been able to find any docs, videos, or blogs that actually explain it.
So far, the best references I have are answers on this site:
This .conf talk that @martin_mueller gave in 2016 and 2017 is a good lispy
resource; it includes demos in the Job Inspector as well as some theory behind best search practices. In fact he also wrote the second Answers link you shared!
2016 Talk
Recording: http://conf.splunk.com/files/2016/recordings/fields-indexed-tokens-and-you.mp4
Slides: http://conf.splunk.com/files/2016/slides/fields-indexed-tokens-and-you.pdf
2017 Talk
Recording: https://conf.splunk.com/files/2017/recordings/fields-indexed-tokens-and-you.mp4
Slides: http://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf