Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why splunk do not scan all events to search a specific keyword?

$
0
0
Suppose I have 1 Lac events with sourcetype = java and i am searching for keyword "xyz" with query: sourcetype=java xyz I think search should scan all 1 Lac events and then return should matched events. But it just scanning 12,457 events and returning 202 matched events. why this so? is it means splunk not searching that keyword into all 1 lac files?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>