Reporting

Cross-app Report Acceleration not working

martin_mueller
SplunkTrust
SplunkTrust

I have built an app containing common knowledge objects such as field extractions, lookups, etc. to share between other apps with different role-based visibility.

Now, the KO app also contains accelerated saved searches, shared globally. Running the search from the KO app uses the report acceleration summary, running the search from a different app such as Search does not use the report acceleration summary.
How can I make the report acceleration summary work in all apps?

To illustrate what I'm seeing, here's a screenshot of the Job Monitor showing the very same search (configured in knowledge with report acceleration fully built, shared globally) run in two different apps with quite different durations.

alt text

1 Solution

MuS
Legend

Hi martin_mueller

just recently asked the support team almost the same question and got this answer:

To answer your question, yes that is to be expected because field extractions often differ by app.  Therefore, you can have 2 identical searches, one in app A and one in app B and they will return different results.  Therefore we currently do not allow sharing of report acceleration across apps.  

To allow for this possibility is being considered for future but it's not been decided on yet.

cheers, MuS

View solution in original post

MuS
Legend

Hi martin_mueller

just recently asked the support team almost the same question and got this answer:

To answer your question, yes that is to be expected because field extractions often differ by app.  Therefore, you can have 2 identical searches, one in app A and one in app B and they will return different results.  Therefore we currently do not allow sharing of report acceleration across apps.  

To allow for this possibility is being considered for future but it's not been decided on yet.

cheers, MuS

martin_mueller
SplunkTrust
SplunkTrust

Damn, that makes sense 😞

Thanks!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...