I tried turning my search into a report and accelerating it but got the " Your report doesn't qualify for acceleration" message..
Here's my search :
| transaction keeporphans=t keepevicted=t IDT,PART
| search environment= (PART=) (IDF=)
| table _time,IDF,IDT,PART,DIAGXdetails,DIAGYdetails,codemeaning,environment
| join IDT type=inner
[ search index=bigdatay sourcetype="logb"
| search (status=)
| table Code,sender,receiver,status,IDT,IDTU,action,filename]
| table _time,sender,receiver,PART,IDF,status,action,IDT,IDTU,DIAGXdetails,DIAGPdetails,codemeaning,filename,Code
| where PART= receiver OR PART= sender
I'm currently running Splunk 6.5.3
How can i improve accelerate this search ?
View solution in original post