We have a report such as -
index=<index name>
( URI=<a certain uri> OR
URI=<a certain uri> OR
URI=<a certain uri> ....
)
| dedup <field name>
| rename <fields>
| eval <new time field>=_time
| table <fields>
| fillnull
Why wouldn’t it qualify for report acceleration?
Your query is not using any transforming/streaming commands and therefore does not qualify. You need to use stats, timechart, etc.
This section has more detailed information:
https://docs.splunk.com/Documentation/Splunk/7.2.5/Knowledge/Aboutsummaryindexing
Great, is there a way to convert the table
command to a streaming command?
You can perform an eval on one of the fields being returned, or add stats, timechart, etc. Any of those should make it qualify.