Transaction Performance Optimization: Using Streamstats as an Alternative
A Splunk administrator is tuning a dashboard that uses `transaction` to correlate web server events. The dashboard frequently times out. The admin reviews the search and sees `transaction client_ip maxspan=1h maxpause=30m`. The dataset contains about 10 million events per hour. The admin suspects that the transaction is causing the timeout. Which action should they take to improve performance while still achieving the grouping?
Quick Answer
The correct answer is to replace `transaction` with `streamstats` to create a session ID, then use `stats` to aggregate. This is because `transaction` is a memory-intensive command that holds all matching events in RAM until the transaction is complete, and with 10 million events per hour and generous `maxspan=1h` and `maxpause=30m` limits, it will overwhelm resources and cause timeouts. On the Splunk SPLK-1003 exam, this scenario tests your understanding of optimizing transaction performance by choosing a more scalable, streaming approach: `streamstats` assigns a session ID based on field values or time windows without holding the entire dataset in memory, and then `stats` groups the results efficiently. A common trap is thinking that simply reducing the `maxspan` or `maxpause` will fix the timeout, but the core issue is the command itself. Remember the memory tip: "Transaction hoards, Streamstats scores" — streamstats processes events one at a time, making it the go-to alternative for large-scale sessionization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Replace transaction with streamstats to create a session ID, then use stats to aggregate
The transaction command is memory-intensive, especially with a large dataset (10 million events per hour) and generous limits (maxspan=1h, maxpause=30m). To improve performance, a more efficient approach is to use streamstats to generate a session ID based on a timeout (e.g., using the time difference between events) and then use stats to group by that ID. This avoids holding all events in memory and processes events in a streaming manner. Option A correctly suggests this method. Option B (maxevents=100) still uses transaction and may truncate valid sessions. Option C reduces limits but may miss legitimate sessions and still uses transaction. Option D increases search job concurrency but does not address the underlying memory issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Replace transaction with streamstats to create a session ID, then use stats to aggregate
Why this is correct
streamstats can process events sequentially and assign IDs, then stats can group without the full overhead of transaction.
- ✗
Add `maxevents=100` to limit events per transaction
Why it's wrong here
Helps but transaction still processes all events in memory.
- ✗
Reduce maxspan to 15m and maxpause to 5m
Why it's wrong here
May still cause performance issues if many events.
- ✗
Increase the search job concurrency
Why it's wrong here
Does not address the root cause; may worsen memory.
Go deeper
Related to this question
About these practice questions
This SPLK-1002 question is part of Courseiva's 475-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SPLK-1002
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A Splunk administrator is troubleshooting a slow search that uses the transaction command. The search correlates events by 'user_uuid' with a maxspan of 1 hour. The administrator suspects that many orphan events (events that never complete a transaction) are causing performance issues. Which approach can help identify and possibly exclude orphan events from the transaction?
medium- A.Increase maxspan to allow more events to complete.
- B.Use the 'mvlist' option to list all user_uuid values.
- ✓ C.Use the 'keepevicted=true' option and then filter out evicted events in a subsequent search.
- D.Add 'closed_txn=1' to the transaction command to only output complete transactions.
Why C: The `keepevicted=true` parameter causes the `transaction` command to output events that were evicted from the transaction window (orphans) with an `evicted` field set to 1. You can then filter out these evicted events in a subsequent search using `where evicted=0`, which isolates only complete transactions and removes the performance overhead of orphan events.
Variation 2. In a Splunk environment, an analyst is using the transaction command to group events from different sources. Which THREE factors are most important to consider when designing the transaction search for optimal performance? (Choose three.)
hard- A.Use the 'mvlist' option to store multiple values.
- B.Use a large maxevents value to ensure all events are captured.
- ✓ C.Apply efficient search-time field extractions to avoid using the transaction command across unindexed fields.
- ✓ D.Limit the time range of the search using maxspan.
- ✓ E.Use fields with low cardinality for grouping.
Why C: Options C, D, and E are correct. Efficient search-time field extractions (C) reduce the overhead of the transaction command by avoiding unindexed field lookups. Limiting the time range with maxspan (D) narrows the search window, reducing the number of events to process. Using fields with low cardinality for grouping (E) minimizes the number of open transactions and memory usage. Option A (mvlist) is not a standard transaction option and does not improve performance; Option B (large maxevents) can degrade performance by consuming excessive memory.
Variation 3. An analyst is using the transaction command to group events by a field that has high cardinality (millions of unique values). The search is taking too long and consuming too much memory. Which approach should be taken to improve performance?
medium- ✓ A.Reduce the cardinality of the field by using a derived field with fewer values.
- B.Use the 'maxspan' option to narrow the time window.
- C.Use the 'mvlist' option to reduce field storage.
- D.Use the 'maxevents' option to limit number of events per transaction.
Why A: High cardinality in the field used by `transaction` causes many open transactions, consuming excessive memory and time. Reducing cardinality (e.g., by using a derived field with fewer unique values) directly addresses this issue. Options B (`maxspan`) and D (`maxevents`) can help limit transactions but do not solve the root cause of high cardinality. Option C (`mvlist`) is not a valid option for the `transaction` command.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SPLK-1002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1002 exam.