Splunk Search

This report cannot be accelerated.

DamageSplunk
Explorer

I've got a simple search which uses stats. I've saved the dashboard and created a scheduled report but when I go to setup summary indexing I get "This report cannot be accelerated."

The goal of this search is to generate summary events every 15 minutes - today it's nearly impossible to query an entire day or week in less than 4 hours search time.

The search is: index=azure_wadlogs sourcetype=WADLogs host=* | eval time=_time | eval itime=_indextime | eval latency=(itime - time) | stats count as NumEvents, avg(latency) as AvgLatency, min(latency) as MinLatency, max(latency) as MaxLatency by Role | sort +Role

What is preventing me from enabling report acceleration?

Tags (1)
0 Karma
1 Solution

masonmorales
Influencer

Does your role allow you to accelerate reports? (i.e. does it have the schedule_search capability?)

Take a look at the docs too: http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports

View solution in original post

masonmorales
Influencer

Does your role allow you to accelerate reports? (i.e. does it have the schedule_search capability?)

Take a look at the docs too: http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports

skoelpin
SplunkTrust
SplunkTrust

If you want to accelerate the search then you need to have a transforming search which is made up of transforming commands.. So take your normalized search and tweek it to include a transformation command

http://docs.splunk.com/Splexicon:Transformingsearch

0 Karma

masonmorales
Influencer
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...