Reporting

Why is my accelerated report with a summary range of 1 year only showing 1 month of data?

a212830
Champion

Hi,

I have a report set up to run nightly at 1:00 am, and I have that report accelerated with a summary range of 1 year. However, I can only get 1 month of data out of the report. Why is that?

Tags (2)
0 Karma

woodcock
Esteemed Legend

Either because you only have 1 month of raw data retained or because the timerange for your report only spans 1 month. Acceleration (or lack thereof) cannot ever cause a search to return different results; it can only effect how quickly the (same) results are returned.

a212830
Champion

OK. Thanks. My understanding of report acceleration must be wrong - I thought report acceleration actually took the data from your search, and put it in "side buckets", allowing you to keep longer term storage for a report, without having to keep the detailed data. Is that wrong?

0 Karma

sowings
Splunk Employee
Splunk Employee

Acceleration (Report Acceleration or its cousin Data Model Acceleration) only keep the accelerated data no longer than the raw data upon which they depend.

0 Karma

woodcock
Esteemed Legend

That is true of Summary Indexing which is another very different way to speed up getting results. Don't forget to close the question by clicking "Accept".

0 Karma

a212830
Champion

So, what does report acceleration do?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...