Splunk Search

What privileges are needed to use tstats summariesonly=t?

reed_kelly
Contributor

We have accelerations turned on and at 100% for a number of our datamodels. I like the speed obtained by using |tstats summariesonly=t. If I remove the summariesonly=t, then the results are the exactly the same, but the search takes 10 times longer.

I would like other users to benefit from the speed boost, but they don't see any results unless I put them in the Admin group. Is there another privilege that I need to grant them to make summariesonly=t work? They already have read access to the datamodel and root object.

1 Solution

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

View solution in original post

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

pappjrcaa
New Member

Confirmed the same requirement in my environment - docs don't shed any light on it. Hoping to hear an answer from Splunk on this.

0 Karma

Lowell
Super Champion

Yup, found another one here. Running Splunk 6.3.5 with ES. What I found is that I have the Admin role, but it works from some apps (like the main ES app, and some of the related ES apps, but not from Search or other custom apps.)

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...