Reporting

Is there a way to limit data acceleration time options? For example, to prevent All Time.

paimonsoror
Builder

I have noticed that I have some users in the environment that are selecting 'All Time' by default on data acceleration. The problem is that some of these users have long term data retention and very expensive searches. I was hoping there was a way to limit the max time range used for acceleration.

For now I have set up some alerts to notify me when someone is using "All Time"

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...