Reporting

Cross-app Report Acceleration not working

martin_mueller
SplunkTrust
SplunkTrust

I have built an app containing common knowledge objects such as field extractions, lookups, etc. to share between other apps with different role-based visibility.

Now, the KO app also contains accelerated saved searches, shared globally. Running the search from the KO app uses the report acceleration summary, running the search from a different app such as Search does not use the report acceleration summary.
How can I make the report acceleration summary work in all apps?

To illustrate what I'm seeing, here's a screenshot of the Job Monitor showing the very same search (configured in knowledge with report acceleration fully built, shared globally) run in two different apps with quite different durations.

alt text

1 Solution

MuS
SplunkTrust
SplunkTrust

Hi martin_mueller

just recently asked the support team almost the same question and got this answer:

To answer your question, yes that is to be expected because field extractions often differ by app.  Therefore, you can have 2 identical searches, one in app A and one in app B and they will return different results.  Therefore we currently do not allow sharing of report acceleration across apps.  

To allow for this possibility is being considered for future but it's not been decided on yet.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi martin_mueller

just recently asked the support team almost the same question and got this answer:

To answer your question, yes that is to be expected because field extractions often differ by app.  Therefore, you can have 2 identical searches, one in app A and one in app B and they will return different results.  Therefore we currently do not allow sharing of report acceleration across apps.  

To allow for this possibility is being considered for future but it's not been decided on yet.

cheers, MuS

martin_mueller
SplunkTrust
SplunkTrust

Damn, that makes sense 😞

Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...