Imagine improving the speed of your searches over 500k times faster and breathe new life into your Splunk environment without more hardware investment. Learn how to use both time and segmentation with fast subsearches to quickly filter events for fast, advanced data correlation. Based on the .conf17 talk “Fields, Indexed Tokens, And You"
Slides PDF link - https://conf.splunk.com/files/2019/slides/FN1407.pdf?podcast=1577146225