Splunk Dev

Cached search job not working in clustered environment

GindiKhangura
Explorer

I used JS to enable the cache flag on the searches running on my dashboard using the idea here (https://community.splunk.com/t5/Dashboards-Visualizations/Can-I-cache-searches-in-Simple-XML-using-t...).

It worked for me when I tested it on a standalone Splunk Enterprise environment. However, when I tried it in a clustered environment it did not work, though I do see that the flag is set to true when I inspect the search's JS object through the browser's developer tools.

The searches run after the flag is set (I use a token to control when it runs), so that isn't the issue.

Does anyone know what the issue could be or where to debug the issue?

-----

Notes:

  • Cannot use saved searches or report acceleration
  • Already using data model acceleration
Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...