Reporting

Report scheduling/acceleration question...

a212830
Champion

Hi,

I need to generate a number of reports about license utilization for different customers, over the past 30 days. Do I need to re-run the past 30 days search every day, or is there a way to run it for one day, and have a history that keeps building? Running it every day for 30 days seems like a waste of resources...

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could enable report acceleration for your report to avoid re-running over old days again and again.
You could use the existing license usage data model or a custom one, accelerate that, and build your 30-day reports off that accelerated data model.
You could run a summary search every day to build the report for yesterday, and run your 30-day reports off that summary index.

martin_mueller
SplunkTrust
SplunkTrust

The first one is the easiest to build - save the report with a time range of 30 days, check the "accelerate" box, select 30 days, save, done. Splunk does the rest underneath.

http://docs.splunk.com/Documentation/Splunk/6.5.2/Report/Acceleratereports

0 Karma

kiril123
Path Finder

Do you need to schedule report as well?

0 Karma

leonphelps_s
Path Finder

No, its like a rolling 30 day window.

0 Karma

a212830
Champion

For the first one, how does that work in practice? I want to report on 30 days, but not have my search query the past 30 days every time.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...