1: 背景:
splunk 的查询语句的是否优化,对是否节省资源有很大的影响。下面说一下大概的方法:
There are a set of basic principles that you can follow to optimize your searches.
-
Retrieve only the required data
-
Move as little data as possible
-
Parallelize as much work as possible
-
Set appropriate time windows (设置合适查询时间)
To implement the search optimization principles, use the following techniques.
-
Filter as much as possible in the initial search
-
Perform joins and lookups on only the required data
-
Perform evaluations on the minimum number of events possible
-
Move commands that bring data to the search head as
本文介绍了如何通过遵循基本优化原则来提升Splunk查询效率,如仅检索必要数据、最小化数据移动、并行化工作及设定合适的时间窗口。通过一个包含lookup和evaluation的实际搜索案例,展示如何通过调整搜索组件的位置来减少资源消耗,例如将过滤条件提前,以减少索引访问次数和事件处理量,从而实现搜索优化。
订阅专栏 解锁全文
1947

被折叠的 条评论
为什么被折叠?



