Dashboards & Visualizations

help with accelerated report with dashboard dynamic parameter value slowness

dhavamanis
Builder

We have dashboard with report query, based on base query its loading fine, if add a filter sitename in addition that time range filter. its taking long time to show results.

base query accelerated with report and added to dashboard:

index="mpsakamai" source=/var/log/httpd/akamai/* site=* ("path=%2F&" OR "path=/&") | bucket _time span=1d | stats count by _time, site,response_code | sort _time desc

modified above query with dynamic parameter:

index="mpsakamai" source=/var/log/httpd/akamai/* site=$site_name$ ("path=%2F&" OR "path=/&") | bucket _time span=1d | stats count by _time, site, response_code | sort _time desc

if i pass sitename as alltime, its fetch results fast. if pass particular site value from dashboard dropdown and its taking long time to fetch the results.

Can you please help us, how to speed up this dashboard refresh faster while choosing the sitename.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

If you change the query up to and including the first reporting command then it will not be eligible for the existing report acceleration summary.

You can solve that like this:

base search | ... | stats count by _time, site, response_code | search site=$site_name$ | sort 0 _time desc

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

If you change the query up to and including the first reporting command then it will not be eligible for the existing report acceleration summary.

You can solve that like this:

base search | ... | stats count by _time, site, response_code | search site=$site_name$ | sort 0 _time desc

dhavamanis
Builder

works fine. Thank you so much!.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...