Reporting

How To Accelerate a Search (issue) ?

egid_la
Explorer

Hi,

I tried turning my search into a report and accelerating it but got the " Your report doesn't qualify for acceleration" message..

Here's my search :

index=bigdata_x sourcetype="loga*"
| transaction keeporphans=t keepevicted=t IDT,PART
| search environment=* (PART=) (IDF=)
| table _time,IDF,IDT,PART,DIAGX_details,DIAGY_details,code_meaning,environment
| join IDT type=inner
[ search index=bigdata_y sourcetype="logb*"
| search (status=*)
| table Code,sender,receiver,status,IDT,IDTU,action,filename]
| table _time,sender,receiver,PART,IDF,status,action,IDT,IDTU,DIAGX_details,DIAGP_details,code_meaning,filename,Code
| where PART= receiver OR PART= sender

I'm currently running Splunk 6.5.3

How can i improve accelerate this search ?

0 Karma
1 Solution
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...