Reporting

Why is report acceleration not working for non-admin users in Splunk Cloud 8.2.2112.1?

jakemcnee95
Engager

Hi All, having an issue where report acceleration is not working for non-admin roles. Report is accelerating correctly when running under the admin user and 'Using summaries for search' is found under the job inspector.

When running the same report under other users, report will not load over certain time periods and does not show this same 'Using summaries for search' confirmation in the job inspector.

Things I have tried for other role in question:

- Confirmed scheduled_search and accelerated_search capabilities are enabled
- Confirmed user has write access to the report
- Confirmed report is in shared app which  the user has access to
- Tried various other capabilities and inheritance from power user role

There is over 26 million events being matched, is there a chance of this role hitting a limit which is preventing the accelerated search functionality? Let me know if you need any more information.

Labels (1)
0 Karma
1 Solution

jakemcnee95
Engager

Solved: We had a search filter setup in the restrict search section of the role editor. This search filter was blocking the report from being accelerated.

View solution in original post

0 Karma

jakemcnee95
Engager

Solved: We had a search filter setup in the restrict search section of the role editor. This search filter was blocking the report from being accelerated.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...