All Apps and Add-ons

How to cache app dashboard to avoid search query every time in Splunk 6.2?

splunk_mkhan
Explorer

I am a new splunk user, I am using trial version of splunk 6.2.
I have made few splunk dashboard to show pie chart of index data. When I am opening these dashboard its taking some time to load data from splunk database. I want to cache these dashboard to avoid loading index every time.
Please help me to achieve this step by step in Splunk 6.2(trial version).
Thanks,
yusuf

Tags (1)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Edit your scheduled report to be accelerated, then ensure your dashboard uses the Report, not an inline search. This way the dashboard will call up the cached results from the accelerated data. In addition, if the dashboard has multiple panels all based on the same search but doing different things to the data, you can set a base search in your dashboard and it only performs that search once for the whole dashboard, not for every panel.

For more information, see:

http://docs.splunk.com/Documentation/Splunk/6.2.3/Report/Acceleratereports
http://docs.splunk.com/Documentation/Splunk/6.2.3/AdvancedDev/PostProcess

--
Jesse Trucks
Minister of Magic

View solution in original post

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Edit your scheduled report to be accelerated, then ensure your dashboard uses the Report, not an inline search. This way the dashboard will call up the cached results from the accelerated data. In addition, if the dashboard has multiple panels all based on the same search but doing different things to the data, you can set a base search in your dashboard and it only performs that search once for the whole dashboard, not for every panel.

For more information, see:

http://docs.splunk.com/Documentation/Splunk/6.2.3/Report/Acceleratereports
http://docs.splunk.com/Documentation/Splunk/6.2.3/AdvancedDev/PostProcess

--
Jesse Trucks
Minister of Magic
0 Karma

splunk_mkhan
Explorer

Thanks for reply jtrucks,
When I am selecting setting option "Report acceleration summaries", showing message
"Report Acceleration Summaries
This is an Enterprise-level feature. It is not available with the installed set of licenses."

Please help me to cache dashboard in trial version.

0 Karma

splunk_mkhan
Explorer

I want to schedule to load dashboard in 24 hours once.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...