Optimizing Transaction Performance — Replacing with stats to Reduce Memory
A Splunk administrator notices that a `transaction` command used for correlating VPN login and logout events is consuming excessive memory and causing search timeouts. The transaction groups events by `user` with `maxspan=12h` and `maxpause=30m`. The VPN logs contain millions of events per day. Which design change would most effectively reduce resource consumption while maintaining the ability to correlate logins and logouts within the same session?
Quick Answer
The core tradeoff in this scenario is between two ways of correlating related events: transaction, which holds every matching event in memory until its grouping boundary, maxspan or maxpause, closes, and stats, which processes events in a streaming fashion and only needs to retain the aggregate values it's computing. For a login/logout pairing, all you actually need per session is the earliest timestamp and the latest timestamp for that user, not the full set of intermediate events. stats earliest(_time) as login, latest(_time) as logout by user delivers exactly that, computing the session boundaries incrementally as events stream through rather than buffering the whole group in memory the way transaction does with a 12-hour maxspan and 30-minute maxpause across millions of daily VPN events. This is a common performance pattern in Splunk: transaction is convenient because it preserves full event detail, but that convenience is exactly what makes it memory-hungry at scale. Whenever a scenario only needs summary values like first/last time, counts, or aggregates rather than the full list of grouped events, replacing transaction with stats, often using earliest/latest, is the standard way to keep the same logical correlation while cutting memory usage dramatically.
⚠ Common exam trap
Splunk often tests the misconception that reducing time windows or event counts in `transaction` solves memory issues, but the real trap is that `transaction` always buffers events in memory, whereas `stats` is a streaming command that avoids this bottleneck entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Replace the transaction command with a stats command using earliest and latest functions on the event type.
Replacing `transaction` with `stats` using `earliest` and `latest` eliminates the in-memory event buffering that causes memory exhaustion. `transaction` holds all events in memory until the transaction boundary (maxspan/maxpause) is reached, which is extremely expensive for millions of VPN events. `stats` processes events in a streaming fashion, computing the first and last timestamps per user without storing the full event list, drastically reducing memory and avoiding timeouts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the maxpause option from the transaction command to simplify grouping.
Why it's wrong here
Removing maxpause would group all events for a user within the maxspan, regardless of gaps, increasing memory use.
- ✗
Reduce maxspan to 4h to limit the time window for grouping events.
Why it's wrong here
This may miss legitimate sessions longer than 4 hours, causing incomplete correlations.
- ✓
Replace the transaction command with a stats command using earliest and latest functions on the event type.
Why this is correct
Using `stats earliest(_time) as login, latest(_time) as logout by user` is much more memory efficient and still captures session boundaries.
- ✗
Add maxevents=2 to the transaction command to limit each transaction to exactly two events.
Why it's wrong here
This could miss sessions with multiple failed logins or reconnects, and still requires transaction processing.
Go deeper
Related to this question
About these practice questions
One of 475 original SPLK-1002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on SPLK-1002
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A Splunk admin notices that a transaction search using the transaction command takes a long time and consumes high memory. The search correlates events by a high-cardinality field (IP address) across multiple indexers. Which optimization technique should be applied first?
hard- A.Use the fields command to remove unnecessary fields before the transaction.
- ✓ B.Increase maxevents to capture more events per transaction.
- C.Use the keepevicted option to retain incomplete transactions.
- D.Use the local parameter to force local processing.
Why B: The correct optimization technique is to increase maxevents, which allows the transaction command to capture more events per transaction, reducing the number of incomplete transactions and improving performance. The fields command reduces data but does not directly address transaction boundaries. The keepevicted option retains incomplete transactions without optimizing performance. The local parameter limits parallelism, increasing time and memory usage on a single indexer.
Variation 2. A Splunk administrator notices that the 'transaction' command is consuming excessive memory when processing a large dataset. The dataset contains events with a common field 'user_id', and the goal is to group events per user within 1 hour. Which approach would best reduce memory usage while still achieving the desired correlation?
hard- A.Use the 'kvform' command instead of transaction.
- ✓ B.Use a subsearch to first filter events and then apply transaction on the smaller set.
- C.Add more fields to the transaction to make it more specific.
- D.Increase the maxspan value to 2 hours to reduce the number of transactions.
Why B: Using a subsearch first reduces the dataset size before the 'transaction' command processes it, directly addressing the memory issue. The 'transaction' command groups events into memory until they are finalized, so a smaller input set means fewer events held simultaneously, lowering memory consumption while still allowing the 1-hour maxspan correlation per user_id.
Variation 3. A Splunk administrator notices that a transaction command is consuming excessive memory and taking too long to complete. The transaction is defined on a field with high cardinality. Which of the following would most effectively reduce memory usage and improve performance?
easy- A.Increase the maxspan value
- B.Remove the maxspan constraint
- C.Set keepevicted=false
- ✓ D.Use a different field with lower cardinality for grouping
Why D: The transaction command groups events based on field values, and high cardinality fields create many unique groups, each requiring memory for state tracking. Using a lower-cardinality field reduces the number of concurrent groups, directly lowering memory consumption and processing time. This addresses the root cause rather than adjusting timeouts or eviction policies.
Variation 4. A Splunk administrator is troubleshooting a search that uses the `transaction` command. The search is taking too long to complete and returning incomplete results. Which TWO changes are most likely to improve performance and accuracy of transaction searches? (Choose TWO.)
medium- A.Remove the `maxspan` parameter to allow transactions of any duration.
- B.Use `mvcombine` to combine multivalued fields before the transaction.
- ✓ C.Use `fields` before `transaction` to include only necessary fields.
- D.Increase the `maxevents` value to allow more events per transaction.
- ✓ E.Set an appropriate `maxspan` value based on the expected duration of correlated events.
Why C: Using the `fields` command before `transaction` reduces the amount of data Splunk must process by retaining only the fields necessary for correlation and output. This minimizes memory and CPU overhead, directly improving search performance and reducing the risk of incomplete results due to resource limits.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SPLK-1002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1002 exam.