All Apps and Add-ons

five minute summaries for splunk app for vmware

matthew_tiffany
Explorer

I was wondering if there was anyway to get the five minute summaries instead of the 20 sec perf data for splunk app for vmware?

Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

There is currently no way to modify the current default of 20 second intervals. In a future release we may allow this to be configurable.

Can you help us understand why you'd like 5 minute summaries? Are you concerned about performance within your current architecture given the lower granularity or something like that?

View solution in original post

0 Karma

sdaniels
Splunk Employee
Splunk Employee

There is currently no way to modify the current default of 20 second intervals. In a future release we may allow this to be configurable.

Can you help us understand why you'd like 5 minute summaries? Are you concerned about performance within your current architecture given the lower granularity or something like that?

0 Karma

jwells
New Member

Hi,

I bring up this solved question because I have the very same problem on my Splunk instance. Was the feature you mention ever introduced?

Thank you

0 Karma

matthew_tiffany
Explorer

I am not currently using summary indexing, or report acceleration, I will look into them though. My search is normally run using the java api.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Ok thanks. Are you currently using summary indexing or report acceleration to speed up your historical search? You should be able to improve your time on your search significantly!

http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Aboutsummaryindexing

0 Karma

matthew_tiffany
Explorer

mainly for my application 20 second intervals are not needed, and with the current data store that splunk is installed it takes hours to run a search for a whole month. I am currently using it for getting usage data.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...