Reporting

Cross-app Report Acceleration not working

martin_mueller
SplunkTrust
SplunkTrust

I have built an app containing common knowledge objects such as field extractions, lookups, etc. to share between other apps with different role-based visibility.

Now, the KO app also contains accelerated saved searches, shared globally. Running the search from the KO app uses the report acceleration summary, running the search from a different app such as Search does not use the report acceleration summary.
How can I make the report acceleration summary work in all apps?

To illustrate what I'm seeing, here's a screenshot of the Job Monitor showing the very same search (configured in knowledge with report acceleration fully built, shared globally) run in two different apps with quite different durations.

alt text

1 Solution

MuS
Legend

Hi martin_mueller

just recently asked the support team almost the same question and got this answer:

To answer your question, yes that is to be expected because field extractions often differ by app.  Therefore, you can have 2 identical searches, one in app A and one in app B and they will return different results.  Therefore we currently do not allow sharing of report acceleration across apps.  

To allow for this possibility is being considered for future but it's not been decided on yet.

cheers, MuS

View solution in original post

MuS
Legend

Hi martin_mueller

just recently asked the support team almost the same question and got this answer:

To answer your question, yes that is to be expected because field extractions often differ by app.  Therefore, you can have 2 identical searches, one in app A and one in app B and they will return different results.  Therefore we currently do not allow sharing of report acceleration across apps.  

To allow for this possibility is being considered for future but it's not been decided on yet.

cheers, MuS

martin_mueller
SplunkTrust
SplunkTrust

Damn, that makes sense 😞

Thanks!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...