Reporting

How often report accelaration check the new data set in HDFS ?

melonman
Motivator

Hi

I am using Hunk and configured report acceleration saved searches. report acceleration automatically checks where there are new data sets that have not been cached.

My Question is how often the report acceleration feature checks new data set in HDFS, and its mechanism.
Is there default value of interval for report acceleration to check the new data sets?
How does the report acceleration keep track of cached/fresh data set?

Appreciated if anyone can point me to the information or readings about this.

Thank you.

1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

It defaults to every 10 minutes, but it can be set on a per saved search basis from the conf file, for more info look at savedsearches.conf. Note that there is a limit to how many report acceleration summary generating searches can run concurrently (defaults to 50% of scheduler's capacity), which means that for busy systems the 10 minute period is only a rough approximation.

auto_summarize.cron_schedule = <cron-string>
* Cron schedule to be used to probe/generate the summaries for this search

View solution in original post

Ledion_Bitincka
Splunk Employee
Splunk Employee

It defaults to every 10 minutes, but it can be set on a per saved search basis from the conf file, for more info look at savedsearches.conf. Note that there is a limit to how many report acceleration summary generating searches can run concurrently (defaults to 50% of scheduler's capacity), which means that for busy systems the 10 minute period is only a rough approximation.

auto_summarize.cron_schedule = <cron-string>
* Cron schedule to be used to probe/generate the summaries for this search
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...