Hi, before Splunk 5 we have created about 40 saved searches that are populating summary index and about 70 other saved searches plus a handful of dashboards that query against the summary index. Now that we've upgraded to version 5, should we convert some (or all) to use Report Acceleration instead? What are some things we need to take into consideration when making that decision?
↧