Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Better search query way in terms of performance

$
0
0
I have below search criteria so let me know best way for this. base search (which have output in table format) [table sourcetype def ghi] sourcetype= 1 check with static lookup and store respective result in "ghi" field sourcetype= 2 check with static lookup and store respective result in "ghi" field

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>