Reporting

Why is report acceleration not working for non-admin users in Splunk Cloud 8.2.2112.1?

jakemcnee95
Engager

Hi All, having an issue where report acceleration is not working for non-admin roles. Report is accelerating correctly when running under the admin user and 'Using summaries for search' is found under the job inspector.

When running the same report under other users, report will not load over certain time periods and does not show this same 'Using summaries for search' confirmation in the job inspector.

Things I have tried for other role in question:

- Confirmed scheduled_search and accelerated_search capabilities are enabled
- Confirmed user has write access to the report
- Confirmed report is in shared app which  the user has access to
- Tried various other capabilities and inheritance from power user role

There is over 26 million events being matched, is there a chance of this role hitting a limit which is preventing the accelerated search functionality? Let me know if you need any more information.

Labels (1)
0 Karma
1 Solution

jakemcnee95
Engager

Solved: We had a search filter setup in the restrict search section of the role editor. This search filter was blocking the report from being accelerated.

View solution in original post

0 Karma

jakemcnee95
Engager

Solved: We had a search filter setup in the restrict search section of the role editor. This search filter was blocking the report from being accelerated.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...