Reporting

Report scheduling/acceleration question...

a212830
Champion

Hi,

I need to generate a number of reports about license utilization for different customers, over the past 30 days. Do I need to re-run the past 30 days search every day, or is there a way to run it for one day, and have a history that keeps building? Running it every day for 30 days seems like a waste of resources...

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could enable report acceleration for your report to avoid re-running over old days again and again.
You could use the existing license usage data model or a custom one, accelerate that, and build your 30-day reports off that accelerated data model.
You could run a summary search every day to build the report for yesterday, and run your 30-day reports off that summary index.

martin_mueller
SplunkTrust
SplunkTrust

The first one is the easiest to build - save the report with a time range of 30 days, check the "accelerate" box, select 30 days, save, done. Splunk does the rest underneath.

http://docs.splunk.com/Documentation/Splunk/6.5.2/Report/Acceleratereports

0 Karma

kiril123
Path Finder

Do you need to schedule report as well?

0 Karma

leonphelps_s
Path Finder

No, its like a rolling 30 day window.

0 Karma

a212830
Champion

For the first one, how does that work in practice? I want to report on 30 days, but not have my search query the past 30 days every time.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...