Back to Floor
Security SPL • Room 1
The tstats Engine
When dealing with billions of security events, standard `search` commands are too slow. Analysts must use `tstats` on accelerated data models.
`tstats` only reads index metadata (tsidx files), making it exponentially faster than reading raw events from disk.
Knowledge Check
Prove your understanding to clear the room (Rewards XP)
Use `tstats` to count the total number of events in the "Malware" datamodel, grouped by `Malware.action`.
Splunk Search Bar
>