Reporting

Creating Incremental Summaries Using Report Acceleration

milanparmar541
Explorer

Hi everyone,

I am trying to accelerating one savedsearch "index=main |stats count by type,severity". Now I want an accelerated summary of "All time" data for the first time only and later, every 10minutes I want to collect an incremental summary of the last 10minutes data on top of the "All time" accelerated summary. Is there any way to achieve this?

Note: I've come across to know the auto_summarize.dispatch.earliest_time parameter which seems directly bound to "Summary range". If I keep earliest_time to -10min(Because auto_summarize.cron_schedule parameter is set to */10 * * * *) then my summary range is also changing from "Alltime" to "1 Day".

0 Karma
Get Updates on the Splunk Community!

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...