Splunk Search

What privileges are needed to use tstats summariesonly=t?

reed_kelly
Contributor

We have accelerations turned on and at 100% for a number of our datamodels. I like the speed obtained by using |tstats summariesonly=t. If I remove the summariesonly=t, then the results are the exactly the same, but the search takes 10 times longer.

I would like other users to benefit from the speed boost, but they don't see any results unless I put them in the Admin group. Is there another privilege that I need to grant them to make summariesonly=t work? They already have read access to the datamodel and root object.

1 Solution

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

View solution in original post

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

pappjrcaa
New Member

Confirmed the same requirement in my environment - docs don't shed any light on it. Hoping to hear an answer from Splunk on this.

0 Karma

Lowell
Super Champion

Yup, found another one here. Running Splunk 6.3.5 with ES. What I found is that I have the Admin role, but it works from some apps (like the main ES app, and some of the related ES apps, but not from Search or other custom apps.)

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...