Archive

This report cannot be accelerated.

Explorer

I've got a simple search which uses stats. I've saved the dashboard and created a scheduled report but when I go to setup summary indexing I get "This report cannot be accelerated."

The goal of this search is to generate summary events every 15 minutes - today it's nearly impossible to query an entire day or week in less than 4 hours search time.

The search is: index=azure_wadlogs sourcetype=WADLogs host=* | eval time=_time | eval itime=_indextime | eval latency=(itime - time) | stats count as NumEvents, avg(latency) as AvgLatency, min(latency) as MinLatency, max(latency) as MaxLatency by Role | sort +Role

What is preventing me from enabling report acceleration?

Tags (1)
0 Karma
1 Solution

Influencer

Does your role allow you to accelerate reports? (i.e. does it have the schedule_search capability?)

Take a look at the docs too: http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports

View solution in original post

Influencer

Does your role allow you to accelerate reports? (i.e. does it have the schedule_search capability?)

Take a look at the docs too: http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports

View solution in original post

SplunkTrust
SplunkTrust

If you want to accelerate the search then you need to have a transforming search which is made up of transforming commands.. So take your normalized search and tweek it to include a transformation command

http://docs.splunk.com/Splexicon:Transformingsearch

0 Karma

Influencer
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!