Reporting

Why is my accelerated report with a summary range of 1 year only showing 1 month of data?

a212830
Champion

Hi,

I have a report set up to run nightly at 1:00 am, and I have that report accelerated with a summary range of 1 year. However, I can only get 1 month of data out of the report. Why is that?

Tags (2)
0 Karma

woodcock
Esteemed Legend

Either because you only have 1 month of raw data retained or because the timerange for your report only spans 1 month. Acceleration (or lack thereof) cannot ever cause a search to return different results; it can only effect how quickly the (same) results are returned.

a212830
Champion

OK. Thanks. My understanding of report acceleration must be wrong - I thought report acceleration actually took the data from your search, and put it in "side buckets", allowing you to keep longer term storage for a report, without having to keep the detailed data. Is that wrong?

0 Karma

sowings
Splunk Employee
Splunk Employee

Acceleration (Report Acceleration or its cousin Data Model Acceleration) only keep the accelerated data no longer than the raw data upon which they depend.

0 Karma

woodcock
Esteemed Legend

That is true of Summary Indexing which is another very different way to speed up getting results. Don't forget to close the question by clicking "Accept".

0 Karma

a212830
Champion

So, what does report acceleration do?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...