<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search and alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121363#M1847</link>
    <description>&lt;P&gt;I think you are making confusions about the &lt;STRONG&gt;schedule&lt;/STRONG&gt; Alert. That  &lt;CODE&gt;-24hr@h to now&lt;/CODE&gt; is the Time Range for the search. For the schedule alert, you just need to specify a single time, like &lt;CODE&gt;* /5 * * * *&lt;/CODE&gt; for example, to say that,  after 5 minutes, your search will start and if the &lt;STRONG&gt;condition is true&lt;/STRONG&gt;, the mail will be sent.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 22 May 2015 16:40:13 GMT</pubDate>
    <dc:creator>stephanefotso</dc:creator>
    <dc:date>2015-05-22T16:40:13Z</dc:date>
    <item>
      <title>search and alerts</title>
      <link>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121362#M1846</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a search which is sceduled and should send an alert. I see it running on scheduled time from job inspector but says no search results found. but if I run same search manually (for last 24hrs) I see results. &lt;BR /&gt;
The scheduled search is set to -24hr@h to now. Is "NOW" is  the reason for not finding results or does it could be something else?&lt;BR /&gt;
I changed the scheduled search to -24h@h to -1m@m to find if this is the reason but I just want to ask if anyone saw this issue?&lt;/P&gt;

&lt;P&gt;The same search worked yesterday but not today. Basically it looks like it is working sometimes and not other times.&lt;/P&gt;

&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 16:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121362#M1846</guid>
      <dc:creator>gudavasr</dc:creator>
      <dc:date>2015-05-22T16:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: search and alerts</title>
      <link>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121363#M1847</link>
      <description>&lt;P&gt;I think you are making confusions about the &lt;STRONG&gt;schedule&lt;/STRONG&gt; Alert. That  &lt;CODE&gt;-24hr@h to now&lt;/CODE&gt; is the Time Range for the search. For the schedule alert, you just need to specify a single time, like &lt;CODE&gt;* /5 * * * *&lt;/CODE&gt; for example, to say that,  after 5 minutes, your search will start and if the &lt;STRONG&gt;condition is true&lt;/STRONG&gt;, the mail will be sent.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 16:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121363#M1847</guid>
      <dc:creator>stephanefotso</dc:creator>
      <dc:date>2015-05-22T16:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: search and alerts</title>
      <link>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121364#M1848</link>
      <description>&lt;P&gt;Hi Gudavasr,&lt;/P&gt;

&lt;P&gt;Hope below link can help you &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Alert/Definescheduledalerts"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Alert/Definescheduledalerts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2015 14:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/search-and-alerts/m-p/121364#M1848</guid>
      <dc:creator>neelamssantosh</dc:creator>
      <dc:date>2015-05-23T14:36:00Z</dc:date>
    </item>
  </channel>
</rss>

