Hello,
Here is what I am facing: I have an accelerated saved search, with All Time summary range, and Timespans 10min, 1d, 1h, 1mon
When calling it to All Time, it runs immediately. When calling it for 2 days period, it still does.
When calling it with a 10h period, it takes a lot longer, although job inspections shows it actually accesses the summaries...
Could someone explain that ?
Hello,
Well I don't understand why would Splunk use the 10minute summaries if I have a Timespan of 1h. Splunk should use ten 1hour summaries to return the search results, and not use the 10minute summaries...
Do you have an answer for that?