<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Schedule an alert in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293145#M5437</link>
    <description>&lt;P&gt;Use earliest as &lt;CODE&gt;-1h@h&lt;/CODE&gt; and latest as &lt;CODE&gt;@h&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2017 21:14:04 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2017-03-23T21:14:04Z</dc:date>
    <item>
      <title>Schedule an alert</title>
      <link>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293141#M5433</link>
      <description>&lt;P&gt;How to schedule an alert to search for last hour data.&lt;BR /&gt;
Ex: I have to schedule Alert to search for 9:00am-10:00am data. My Alert is scheduled at 15th min of every hour(15 */1 * * *). At 10:15 am, My alert runs, But I need it to search for last hour data(9-10am). what should be the earliest and the latest  time settings?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:21:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293141#M5433</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2017-03-23T20:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Schedule an alert</title>
      <link>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293142#M5434</link>
      <description>&lt;P&gt;Go to &lt;CODE&gt;Save As&lt;/CODE&gt; in the upper right corner after you have a search in the search bar and select &lt;CODE&gt;Alert&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;There will be 2 fields &lt;CODE&gt;Earliest&lt;/CODE&gt; and &lt;CODE&gt;Latest&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The &lt;CODE&gt;Earliest&lt;/CODE&gt; field should have &lt;CODE&gt;-1h@h&lt;/CODE&gt;&lt;BR /&gt;
The &lt;CODE&gt;Latest&lt;/CODE&gt; field should have &lt;CODE&gt;now&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This will set a 1 hour window of the previous hour &lt;/P&gt;

&lt;P&gt;You will also see the timeranges populate once you enter in those values&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293142#M5434</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-03-23T20:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Schedule an alert</title>
      <link>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293143#M5435</link>
      <description>&lt;P&gt;If I use latest time as now, then it will search for the data from 9:00-10:15 right? I just need 1 hr data&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 20:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293143#M5435</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2017-03-23T20:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Schedule an alert</title>
      <link>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293144#M5436</link>
      <description>&lt;P&gt;Just use earliest=-1h@h latest=@h to search from 9-10 (assuming a 10:15/30/45 search run time.&lt;BR /&gt;
Details &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/SearchTimeModifiers"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 21:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293144#M5436</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-03-23T21:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Schedule an alert</title>
      <link>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293145#M5437</link>
      <description>&lt;P&gt;Use earliest as &lt;CODE&gt;-1h@h&lt;/CODE&gt; and latest as &lt;CODE&gt;@h&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 21:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Schedule-an-alert/m-p/293145#M5437</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-03-23T21:14:04Z</dc:date>
    </item>
  </channel>
</rss>

