Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Faster way to find first occurrence of "duplicate" events

$
0
0

I am trying to chart initial logins over time as follows:

index="abc" sourcetype="*apache_access" NOT remote_ident="-" | table _time remote_ident | stats earliest(_time) as _time BY remote_ident | timechart count

but the search is excruciatingly slow.

Any performance tips would be appreciated.

Thanks,

-Yisroel


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>