<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert setup in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460649#M8159</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You could give the below conf to achieve the functionality.&lt;BR /&gt;
Please try and let us know.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   Cron : 0-59/15 * * * *  [Runs a search every 15 min,round the clock - 00,15,30,45 ]
   Earliest : -15m@m [ Give the window of search for the past 15 min ]
   Latest : now
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 11 Dec 2019 19:48:51 GMT</pubDate>
    <dc:creator>dindu</dc:creator>
    <dc:date>2019-12-11T19:48:51Z</dc:date>
    <item>
      <title>Alert setup</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460647#M8157</link>
      <description>&lt;P&gt;Hi all!&lt;BR /&gt;
Want to set up an alert. &lt;BR /&gt;
I want it to alert when the value is 0 for more than 15 min.&lt;BR /&gt;
What shall write in cron, earliest etc.&lt;BR /&gt;
I have the search already. &lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 19:00:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460647#M8157</guid>
      <dc:creator>amirarsalan</dc:creator>
      <dc:date>2019-12-11T19:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alert setup</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460648#M8158</link>
      <description>&lt;P&gt;What you put in the cron, earliest, and latest boxes depends on how often you want your search to run and over what time frame.  We need more information.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 19:18:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460648#M8158</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-12-11T19:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alert setup</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460649#M8159</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You could give the below conf to achieve the functionality.&lt;BR /&gt;
Please try and let us know.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   Cron : 0-59/15 * * * *  [Runs a search every 15 min,round the clock - 00,15,30,45 ]
   Earliest : -15m@m [ Give the window of search for the past 15 min ]
   Latest : now
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 11 Dec 2019 19:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460649#M8159</guid>
      <dc:creator>dindu</dc:creator>
      <dc:date>2019-12-11T19:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Alert setup</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460650#M8160</link>
      <description>&lt;P&gt;Thank You @dindu &lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 07:47:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460650#M8160</guid>
      <dc:creator>amirarsalan</dc:creator>
      <dc:date>2019-12-12T07:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alert setup</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460651#M8161</link>
      <description>&lt;P&gt;Thanks   &lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 14:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-setup/m-p/460651#M8161</guid>
      <dc:creator>dindu</dc:creator>
      <dc:date>2019-12-12T14:49:47Z</dc:date>
    </item>
  </channel>
</rss>

