Monitoring Splunk

Deployment monitor accelerated searches not working at all?



I have a couple of servers that were 4.x and I updated them to 5.0.2. I also installed the latest Deployment Monitor application.

However, now accelerated searches are not working at all. In Manager -> Report Acceleration Summaries they are all listed like this:

    0.0000  0 Last Access: Never    Summarization not started Updated: Never

    0.0000  0 Last Access: Never    Summarization not started Updated: Never

If I go to a search in Manager -> Searches and reports and select one (for example sourcetypes_summary_10m) I can see that the search is:


And it's accelerated to 3 months summary range. However, when I click on Save I get the following error:

Encountered the following error while trying to update: In handler 'savedsearch': This search cannot be accelerated

Checking the macro it looks ok. Puzzled. 😕

Path Finder

See "How Searches Qualify for Acceleration". I was having this same issue... to accelerate the search has to chart/stat/table/etc... not just return a set of events.

0 Karma

Splunk Employee
Splunk Employee

I suspect you might be hitting a bug in Splunk core that can cause report acceleration not to function as expected. Have you opened a support case yet?

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...