Splunk Search

What privileges are needed to use tstats summariesonly=t?

reed_kelly
Contributor

We have accelerations turned on and at 100% for a number of our datamodels. I like the speed obtained by using |tstats summariesonly=t. If I remove the summariesonly=t, then the results are the exactly the same, but the search takes 10 times longer.

I would like other users to benefit from the speed boost, but they don't see any results unless I put them in the Admin group. Is there another privilege that I need to grant them to make summariesonly=t work? They already have read access to the datamodel and root object.

1 Solution

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

View solution in original post

reed_kelly
Contributor

I found a work-around by adding allow_old_summaries=t. I'm just confused as to why summariesonly=t only works without Admin by adding allow_old_summaries=t.

pappjrcaa
New Member

Confirmed the same requirement in my environment - docs don't shed any light on it. Hoping to hear an answer from Splunk on this.

0 Karma

Lowell
Super Champion

Yup, found another one here. Running Splunk 6.3.5 with ES. What I found is that I have the Admin role, but it works from some apps (like the main ES app, and some of the related ES apps, but not from Search or other custom apps.)

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...