Question 1
A financial services firm has a critical fraud detection dashboard that monitors real-time transactions. The primary panel, which identifies suspicious transaction volumes per user, is experiencing significant performance degradation. The panel is powered by the following inline search:
index=transactions earliest=-15m | stats count by user_id | where count > 100
This search is one of five similar high-frequency searches on the same dashboard, all querying the transactions index. The dashboard must refresh every 5 minutes with data no more than 15 minutes old. The CISO has mandated that the dashboard's load time must not exceed 10 seconds. Given the high volume of transaction data, which approach offers the most efficient and scalable solution to meet these requirements?
Answer and explanation
Correct answer: B
The most efficient solution is to use a base search with post-processing. A single base search retrieves the raw data once, and its results are cached. Each panel's post-process search then runs against this small, cached result set, which is significantly faster than each panel running a full search against the entire index. This design pattern minimizes the load on the indexers and dramatically improves dashboard performance, especially when multiple panels query the same base data.