Reporting
Highlighted

Why doesn’t the report qualify for report acceleration?

Ultra Champion

We have a report such as -

index=<index name>
            (  URI=<a certain uri> OR 
               URI=<a certain uri> OR 
               URI=<a certain uri> ....
            )
| dedup <field name>
| rename <fields>
| eval <new time field>=_time
| table <fields>
| fillnull

Why wouldn’t it qualify for report acceleration?

Tags (2)
0 Karma
Highlighted

Re: Why doesn’t the report qualify for report acceleration?

Motivator

Your query is not using any transforming/streaming commands and therefore does not qualify. You need to use stats, timechart, etc.

This section has more detailed information:
https://docs.splunk.com/Documentation/Splunk/7.2.5/Knowledge/Aboutsummaryindexing

0 Karma
Highlighted

Re: Why doesn’t the report qualify for report acceleration?

Ultra Champion

Great, is there a way to convert the table command to a streaming command?

0 Karma
Highlighted

Re: Why doesn’t the report qualify for report acceleration?

Motivator

You can perform an eval on one of the fields being returned, or add stats, timechart, etc. Any of those should make it qualify.

0 Karma