I have tried below sample search for acceleration but they are not allowed.
index="_internal"| table host source
index=_internal|streamstats sum(bytes) as byte by sourcetype|stats count by host source byte
as per splunk docs, it should contain transforming commands and I hope table is transforming commands. so first query should be able to accelerate but it won't accelerate.
Can you please help me to understand why those searches are not allowed to be accelerated?
Thanks
@richgalloway I get message "This report cannot be accelerated."
Yeah, that's not a helpful error message. See the docs at https://docs.splunk.com/Documentation/Splunk/8.2.1/Report/Acceleratereports#How_reports_qualify_for_... for reasons why a report can't be accelerated. Share the search if you need extra eyes to check it.
@ips_mandar what version of Splunk are you using?
Report Acceleration has been problem in Splunk for awhile, as nobody seems to use the feature – see https://community.splunk.com/t5/Reporting/Splunk-8-0-2-report-acceleration-broken-for-reports-using/...for more details.