<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert report date range in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546677#M10392</link>
    <description>&lt;P&gt;Thank you so much for this it worked out for me.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Apr 2021 09:12:50 GMT</pubDate>
    <dc:creator>Engineer_Zen</dc:creator>
    <dc:date>2021-04-05T09:12:50Z</dc:date>
    <item>
      <title>Alert report date range</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546199#M10382</link>
      <description>&lt;P&gt;So when I use&amp;nbsp;&lt;/P&gt;&lt;P&gt;Report Start=$job.earliestTime$&lt;/P&gt;&lt;P&gt;Report End=$job.latestTime$&lt;/P&gt;&lt;P&gt;I am getting the below in my mail as response&amp;nbsp;&lt;/P&gt;&lt;P&gt;Report Start=2021-03-24T06:00:00.000-05:00&lt;/P&gt;&lt;P&gt;Report End=2021-03-31T06:03:00.000-05:00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from the dates what are the other fields I am getting?&lt;/P&gt;&lt;P&gt;Is there anyway I can change them to proper IST&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/172209"&gt;@mayurr98&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 11:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546199#M10382</guid>
      <dc:creator>Engineer_Zen</dc:creator>
      <dc:date>2021-03-31T11:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alert report date range</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546219#M10386</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233001"&gt;@Engineer_Zen&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Check this page for all available tokens for email alert action.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/EmailNotificationTokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/EmailNotificationTokens&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 13:52:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546219#M10386</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-31T13:52:11Z</dc:date>
    </item>
    <item>
      <title>Alert report date range</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546231#M10387</link>
      <description>&lt;P&gt;You're getting two fields: Report Start and Report End.&amp;nbsp; Both contain a single value which a timestamp in a standard format (year-month-dayThour:minute:second.millisecond-timeZoneOffsetFromUTC).&lt;/P&gt;&lt;P&gt;You can use the strftime function to display the timestamps in a different format.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval ReportStart=strftime($job.earliestTime$, "%Y-%m-%d %H:%M:%S%Z")&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 14:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546231#M10387</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-31T14:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Alert report date range</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546677#M10392</link>
      <description>&lt;P&gt;Thank you so much for this it worked out for me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 09:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546677#M10392</guid>
      <dc:creator>Engineer_Zen</dc:creator>
      <dc:date>2021-04-05T09:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Alert report date range</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546704#M10393</link>
      <description>&lt;P&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 12:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-report-date-range/m-p/546704#M10393</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-05T12:35:19Z</dc:date>
    </item>
  </channel>
</rss>

