Using event sampling
Like the fact that you only need a drop of blood to test for the amount of sugar and sodium levels in your blood, you often only need a small amount of data from large datasets to make conclusions to build accurate searches. When developing and testing in Splunk, event sampling can be particularly useful against large datasets:

Event sampling uses a sample ratio value that reduces the number of results. If a typical search result returns 1,000 events, a 1:10
event sampling ratio will return 100 events. As you can see from the previous screenshot, these ratios can significantly cut the amount of data searched, and can range from a fairly large ratio (which can be set using the Custom...
setting) to one as small as 1:100,000
(or even smaller, again using the Custom...
setting).
This is not suitable for searches for which you need accurate counts. This is, however, perfect when you are testing your searches as they will return significantly faster. Much of the time you will...