<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: report cannot be accelerated in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534707#M8674</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;I get message "&lt;SPAN&gt;This report cannot be accelerated.&lt;/SPAN&gt;"&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2021 14:58:27 GMT</pubDate>
    <dc:creator>ips_mandar</dc:creator>
    <dc:date>2021-01-04T14:58:27Z</dc:date>
    <item>
      <title>report cannot be accelerated</title>
      <link>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534674#M8671</link>
      <description>&lt;P&gt;I have tried below sample search for acceleration but they are not allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_internal"| table host source&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;index=_internal|streamstats sum(bytes) as byte by sourcetype|stats count by host source byte&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;as per splunk docs, it should contain transforming commands and I hope table is transforming commands. so first query&amp;nbsp; should be able to accelerate but it won't accelerate.&lt;BR /&gt;Can you please help me to understand why those searches are not allowed to be accelerated?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 10:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534674#M8671</guid>
      <dc:creator>ips_mandar</dc:creator>
      <dc:date>2021-01-04T10:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: report cannot be accelerated</title>
      <link>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534699#M8672</link>
      <description>What error message do you get when you try to accelerate them?</description>
      <pubDate>Mon, 04 Jan 2021 14:11:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534699#M8672</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-04T14:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: report cannot be accelerated</title>
      <link>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534707#M8674</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;I get message "&lt;SPAN&gt;This report cannot be accelerated.&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 14:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/534707#M8674</guid>
      <dc:creator>ips_mandar</dc:creator>
      <dc:date>2021-01-04T14:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: report cannot be accelerated</title>
      <link>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/560657#M9361</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/95326"&gt;@ips_mandar&lt;/a&gt;&amp;nbsp;what version of Splunk are you using?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Report Acceleration has been problem in Splunk for awhile, as nobody seems to use the feature – see&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Reporting/Splunk-8-0-2-report-acceleration-broken-for-reports-using/m-p/472290" target="_blank"&gt;https://community.splunk.com/t5/Reporting/Splunk-8-0-2-report-acceleration-broken-for-reports-using/m-p/472290 &lt;/A&gt;for more details.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 21:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/560657#M9361</guid>
      <dc:creator>orion44</dc:creator>
      <dc:date>2021-07-23T21:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: report cannot be accelerated</title>
      <link>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/560681#M9365</link>
      <description>&lt;P&gt;Yeah, that's not a helpful error message.&amp;nbsp; See the docs at &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/Report/Acceleratereports#How_reports_qualify_for_report_acceleration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/Report/Acceleratereports#How_reports_qualify_for_report_acceleration&lt;/A&gt; for reasons why a report can't be accelerated.&amp;nbsp; Share the search if you need extra eyes to check it.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 15:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/report-cannot-be-accelerated/m-p/560681#M9365</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-24T15:59:37Z</dc:date>
    </item>
  </channel>
</rss>

