<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question regarding timeframes and behaviour of delayed alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Question-regarding-timeframes-and-behaviour-of-delayed-alerts/m-p/387119#M6801</link>
    <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;When I schedule a search in Splunk to run at 0:00 and let’s say select the timeframe in the alert of -6h to now. What happens if due to technical issues the search is delayed and runs at 6 AM? Will it now search from 0:00 to 6:00 instead?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Yes&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;When a search is delayed, will the now() command in the search refer back to the “old” scheduled date or will it accordingly use the date of runtime?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;CODE&gt;now&lt;/CODE&gt; is always the time the search runs, not when it was scheduled.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;What happens if you schedule a hourly search but due to technical issues no search can run in a 90m time window. Will the delayed search run together with the next search or will it be skipped?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;The search will be skipped.&lt;/P&gt;</description>
    <pubDate>Sun, 26 May 2019 14:12:14 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-05-26T14:12:14Z</dc:date>
    <item>
      <title>Question regarding timeframes and behaviour of delayed alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Question-regarding-timeframes-and-behaviour-of-delayed-alerts/m-p/387118#M6800</link>
      <description>&lt;P&gt;Heyho!&lt;/P&gt;

&lt;P&gt;I am currently working on putting together a summary index and would like to do it via an alert.&lt;BR /&gt;
The basics are all clear on how to set an alert, scheduling, writing into the index and so on.&lt;BR /&gt;
However I haven’t been able to find any best practice info here and info on how splunk behaves on delayed alerts (not delayed indexing).&lt;/P&gt;

&lt;P&gt;So the Alert I am setting up (and this is already working in a csv) is doing a search for 6h which is at least full 24h ago, and it snaps to the last completed 6h batch of the previous day ( 0,6,12,18). So if you run a search on the 26. of May at 6:01 or at 11:55 it will automatically search for the timeframe of 25. May at 0:00 to 6:00. And that’s all fine in itself, no assistance needed.&lt;/P&gt;

&lt;P&gt;What I do not know though is how splunk alerts usually behave.&lt;BR /&gt;
When I schedule a search in Splunk to run at 0:00 and let’s say select the timeframe in the alert of -6h to now. What happens if due to technical issues the search is delayed and runs at 6 AM? Will it now search from 0:00 to 6:00 instead?&lt;BR /&gt;
When a search is delayed, will the now() command in the search refer back to the “old” scheduled date or will it accordingly use the date of runtime?&lt;BR /&gt;
What happens if you schedule a hourly search but due to technical issues no search can run in a 90m time window. Will the delayed search run together with the next search or will it be skipped?&lt;/P&gt;

&lt;P&gt;With using these 6h intervals I mentioned before in my plans, do you think that all issues are minimized as far as it gets or do you have any other recommendations?&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2019 08:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Question-regarding-timeframes-and-behaviour-of-delayed-alerts/m-p/387118#M6800</guid>
      <dc:creator>Bastelhoff</dc:creator>
      <dc:date>2019-05-26T08:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding timeframes and behaviour of delayed alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Question-regarding-timeframes-and-behaviour-of-delayed-alerts/m-p/387119#M6801</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;When I schedule a search in Splunk to run at 0:00 and let’s say select the timeframe in the alert of -6h to now. What happens if due to technical issues the search is delayed and runs at 6 AM? Will it now search from 0:00 to 6:00 instead?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Yes&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;When a search is delayed, will the now() command in the search refer back to the “old” scheduled date or will it accordingly use the date of runtime?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;CODE&gt;now&lt;/CODE&gt; is always the time the search runs, not when it was scheduled.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;What happens if you schedule a hourly search but due to technical issues no search can run in a 90m time window. Will the delayed search run together with the next search or will it be skipped?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;The search will be skipped.&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2019 14:12:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Question-regarding-timeframes-and-behaviour-of-delayed-alerts/m-p/387119#M6801</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-26T14:12:14Z</dc:date>
    </item>
  </channel>
</rss>

