Splunk Search

What privileges are needed to use tstats summariesonly=t?

reed_kelly
Contributor

We have accelerations turned on and at 100% for a number of our datamodels. I like the speed obtained by using |tstats summariesonly=t. If I remove the summariesonly=t, then the results are the exactly the same, but the search takes 10 times longer.

I would like other users to benefit from the speed boost, but they don't see any results unless I put them in the Admin group. Is there another privilege that I need to grant them to make summariesonly=t work? They already have read access to the datamodel and root object.

1 Solution

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

View solution in original post

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

pappjrcaa
New Member

Confirmed the same requirement in my environment - docs don't shed any light on it. Hoping to hear an answer from Splunk on this.

0 Karma

Lowell
Super Champion

Yup, found another one here. Running Splunk 6.3.5 with ES. What I found is that I have the Admin role, but it works from some apps (like the main ES app, and some of the related ES apps, but not from Search or other custom apps.)

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...