Reporting

Why is report acceleration not working for non-admin users in Splunk Cloud 8.2.2112.1?

jakemcnee95
Engager

Hi All, having an issue where report acceleration is not working for non-admin roles. Report is accelerating correctly when running under the admin user and 'Using summaries for search' is found under the job inspector.

When running the same report under other users, report will not load over certain time periods and does not show this same 'Using summaries for search' confirmation in the job inspector.

Things I have tried for other role in question:

- Confirmed scheduled_search and accelerated_search capabilities are enabled
- Confirmed user has write access to the report
- Confirmed report is in shared app which  the user has access to
- Tried various other capabilities and inheritance from power user role

There is over 26 million events being matched, is there a chance of this role hitting a limit which is preventing the accelerated search functionality? Let me know if you need any more information.

Labels (1)
0 Karma
1 Solution

jakemcnee95
Engager

Solved: We had a search filter setup in the restrict search section of the role editor. This search filter was blocking the report from being accelerated.

View solution in original post

0 Karma

jakemcnee95
Engager

Solved: We had a search filter setup in the restrict search section of the role editor. This search filter was blocking the report from being accelerated.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...