Back to Floor
Security SPL • Room 1

The tstats Engine

When dealing with billions of security events, standard `search` commands are too slow. Analysts must use `tstats` on accelerated data models.

`tstats` only reads index metadata (tsidx files), making it exponentially faster than reading raw events from disk.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
Use `tstats` to count the total number of events in the "Malware" datamodel, grouped by `Malware.action`.
Splunk Search Bar
>