I understand that using "Summary indexing", the Time Range is important as it can create gaps or overlaps.
But how does it work with "Report acceleration" (and "Data model acceleration" by the way)? Since Splunk creates automatically the summaries over a certain "Summary Range", is the "Time Range" field relevant?
What should I enter in the Time Range field for my example (see attachment) ?
The time-range specifies how far back to run the backfill and also how much
tsidx data to keep. If you say
6 months, then an automatic backfill process will run to back-generate the
tsidx for this report. If you then search older than 6 months, the benefits of acceleration will not be preset but if you still have raw data, your search will complete.