As we start looking ahead to .conf2015, we thought it would be good to share some highlights of past .conf sessions. In the first of a series of .conf2014 #TBT highlights, we revisit Julian Harty’s presentation of Splunk Search Optimization.
The simplicity and variability of searches can be a blessing and a curse. How can I tell if searches are really efficient? OK, Splunk has a job inspector, but what do all the options mean? And am I using the right commands for my goal? Is there a better way to do this? This session reviews the details around how a search is performed, the use of job inspector, search log, and gives a review of where and when to use certain commands.
For the full recording, check out Splunk Search Optimization (using Splunk).
We look forward to sharing more of these over the course of the year as we get closer to the 6th annual Splunk worldwide user conference in Las Vegas in September.