Reporting

How to configure auto_summarize.timespan for accelerated reports to increase the minimum timespan to 1 day?

sistemistiposta
Path Finder

Hello splunk users,

I have some new-by questions about accelerated reports. I have accelerated a report simply by clicking on "Accelerate Report".
Good! It works!

In report acceleration summaries, Summary Detail I see the auto Timespans, even if I set in savedsearch.conf:

[MyAcceleratedSearch]
...
auto_summarize.timespan = 1d

This is what I see in Summary Detail:

Summarization Load  0.0355
Access Count    3 Last Access: 2h 41m ago
Size on Disk    1299.68MB
Summary Range   365 days
Timespans   10min, 10s, 1d, 1h, 1min, 1s
Buckets     1401
Chunks  166359

Since I would save disk space and I'm not interested on data every second (my search is ...| timechart span=1d) I would like to increase the minimum time span to 1d.

How can I achieve this?

Thank you very much
Best Regards

0 Karma
1 Solution

TiagoTLD1
Communicator

Hello,

I reached your question due the same strange behaviour. Here is what I got:

First, do these changes on Advanced_Edit in "Searches, Reports and Alerts". That way, you don't need a restart to make the parameters "online".

Second
Splunk takes the finest granularity that you specify in auto_summarize.timespan. So if you specify 10s, you are kind of "guaranteeing that you have that minimum granularity". Splunk will probably use other greater granularities, but that's not our business.

So please try altering the timespan in Advanced_Edit and then Rebuild the Summary.

View solution in original post

sistemistiposta
Path Finder

Hello,
I verified that restarting Splunk it works.
I can't find "Advanced_Edit". Maybe is this not present in Splunk 6.2?

Thank you very much

0 Karma

TiagoTLD1
Communicator

Yes probably in 6.2 it isn't there yet (sorry).

Feel free to mark this as answered, I'm sure it will solve other people's headaches.

0 Karma

TiagoTLD1
Communicator

Hello,

I reached your question due the same strange behaviour. Here is what I got:

First, do these changes on Advanced_Edit in "Searches, Reports and Alerts". That way, you don't need a restart to make the parameters "online".

Second
Splunk takes the finest granularity that you specify in auto_summarize.timespan. So if you specify 10s, you are kind of "guaranteeing that you have that minimum granularity". Splunk will probably use other greater granularities, but that's not our business.

So please try altering the timespan in Advanced_Edit and then Rebuild the Summary.

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...