- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why does running an accelerated saved search work for a large time period ("All Time") but not with smaller ones ("10h")?

TiagoTLD1
Communicator
02-22-2017
08:13 AM
Hello,
Here is what I am facing: I have an accelerated saved search, with All Time summary range, and Timespans 10min, 1d, 1h, 1mon
When calling it to All Time, it runs immediately. When calling it for 2 days period, it still does.
When calling it with a 10h period, it takes a lot longer, although job inspections shows it actually accesses the summaries...
Could someone explain that ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

TiagoTLD1
Communicator
02-23-2017
01:05 AM
Hello,
Well I don't understand why would Splunk use the 10minute summaries if I have a Timespan of 1h. Splunk should use ten 1hour summaries to return the search results, and not use the 10minute summaries...
Do you have an answer for that?
