Reporting

How to configure auto_summarize.timespan for accelerated reports to increase the minimum timespan to 1 day?

Path Finder

Hello splunk users,

I have some new-by questions about accelerated reports. I have accelerated a report simply by clicking on "Accelerate Report".
Good! It works!

In report acceleration summaries, Summary Detail I see the auto Timespans, even if I set in savedsearch.conf:

[MyAcceleratedSearch]
...
auto_summarize.timespan = 1d

This is what I see in Summary Detail:

Summarization Load  0.0355
Access Count    3 Last Access: 2h 41m ago
Size on Disk    1299.68MB
Summary Range   365 days
Timespans   10min, 10s, 1d, 1h, 1min, 1s
Buckets     1401
Chunks  166359

Since I would save disk space and I'm not interested on data every second (my search is ...| timechart span=1d) I would like to increase the minimum time span to 1d.

How can I achieve this?

Thank you very much
Best Regards

0 Karma
1 Solution

Communicator

Hello,

I reached your question due the same strange behaviour. Here is what I got:

First, do these changes on Advanced_Edit in "Searches, Reports and Alerts". That way, you don't need a restart to make the parameters "online".

Second
Splunk takes the finest granularity that you specify in auto_summarize.timespan. So if you specify 10s, you are kind of "guaranteeing that you have that minimum granularity". Splunk will probably use other greater granularities, but that's not our business.

So please try altering the timespan in Advanced_Edit and then Rebuild the Summary.

View solution in original post

Path Finder

Hello,
I verified that restarting Splunk it works.
I can't find "Advanced_Edit". Maybe is this not present in Splunk 6.2?

Thank you very much

0 Karma

Communicator

Yes probably in 6.2 it isn't there yet (sorry).

Feel free to mark this as answered, I'm sure it will solve other people's headaches.

0 Karma

Communicator

Hello,

I reached your question due the same strange behaviour. Here is what I got:

First, do these changes on Advanced_Edit in "Searches, Reports and Alerts". That way, you don't need a restart to make the parameters "online".

Second
Splunk takes the finest granularity that you specify in auto_summarize.timespan. So if you specify 10s, you are kind of "guaranteeing that you have that minimum granularity". Splunk will probably use other greater granularities, but that's not our business.

So please try altering the timespan in Advanced_Edit and then Rebuild the Summary.

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!