Reporting

report acceleration besides existing job server

Starlette
Contributor

hi there

Should accelerated reports configed with sh1 be visible and picked up with sh2?
Thats the basic question, the idea behind this is that i configed the searches from a jobserver but the main indexer isnt use them.
So this is not a set for sh pooling. Iam also curious whats best pratice if I using report accelation against si cube indexes. any tips for this as well?

chrz

hexx
Splunk Employee
Splunk Employee

Currently, if one defines report accelerations on a 'job server' isolated search-head, other search-heads will not be aware of the summaries created on the indexers. These summaries are scoped to the search-head or search-head pool where the report acceleration was defined, so unless they are part of the same search-head pool, the other search-heads will not be aware of their presence, nor is there are why to make them manually aware.

Note that segregating the scheduling of report acceleration on a job server would yield almost no benefit, as report acceleration activity happens only on the indexers and the search-head does almost no work other than record-keeping.

That being said, if you feel strongly that this functionality should be provided (for the purpose of type-based search activity segregation, for example), by all means please file an enhancement request for it.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...