<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled Searches delayed by one hour in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463588#M191501</link>
    <description>&lt;P&gt;Thank you, guys. The mail idea brought me on the right track.&lt;/P&gt;

&lt;P&gt;The email apparently sometimes gets quarantined because of its attachment and then released automatically an hour later.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Feb 2020 16:41:26 GMT</pubDate>
    <dc:creator>omuelle1</dc:creator>
    <dc:date>2020-02-07T16:41:26Z</dc:date>
    <item>
      <title>Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463581#M191494</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have lately seen an issue that some scheduled alerts that contain attachments seem to get emailed to me one hour later than scheduled. I assume this has to do with volume of the alerts and searches scheduled but I haven't been to able to nail it down. When I look in the metadata for information about the delayed scheduled search it does show that it ran at the scheduled time, however the email alert often arrives exactly one hour later in my inbox.&lt;/P&gt;

&lt;P&gt;Has anyone experience with this kind of issue?&lt;/P&gt;

&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 12:37:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463581#M191494</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2020-02-07T12:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463582#M191495</link>
      <description>&lt;P&gt;Can you see from the _internal logs when the email was sent. Was it at the anticipated time, or shortly before recieved?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 12:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463582#M191495</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-07T12:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463583#M191496</link>
      <description>&lt;P&gt;The exactly one hour part makes me think timezone related for some reason, mainly as we've had to deal with GMT\BST data issues here, possibility at all?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 15:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463583#M191496</guid>
      <dc:creator>paulbannister</dc:creator>
      <dc:date>2020-02-07T15:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463584#M191497</link>
      <description>&lt;P&gt;Could well be, reports are scheduled based on the TZ settings of the user who scheduled them.&lt;BR /&gt;
If the user has the wrong TZ set, they will defer according to that offset.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 15:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463584#M191497</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-07T15:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463585#M191498</link>
      <description>&lt;P&gt;^ Exactly this, thanks for expanding&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 15:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463585#M191498</guid>
      <dc:creator>paulbannister</dc:creator>
      <dc:date>2020-02-07T15:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463586#M191499</link>
      <description>&lt;P&gt;I don't think it's the TZ since they are delayed only some of the time.&lt;/P&gt;

&lt;P&gt;So the alert fired at 6:00 AM, when it is scheduled to run:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2020-02-07 06:00:27,173 -0500 INFO  sendemail:134 - Sending email. subject="Splunk Alert: 24 Hour Remote Country Login with MFA  Check", results_link="https://XXXX.splunkcloud.com/app/XX_custom_app/@go?sid=scheduler_c2VjX2das9saXZlci5tdWVsXXXbGVyQG9tZy5jcdasdmhvbWcuY29t_T01HX2N1c3RvbV9hcHA__RMD5a1b9cc0db37475e5_at_1581073200_64487", recipients="[u'XXX@XXX.com']", server="XX.XX.XX.1:25"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However the email arrived in my inbox at 7 AM. Yesterday it came at 6 AM as scheduled, so it's not very consistent. But when it is delayed it is delayed but 1 hour.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 16:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463586#M191499</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2020-02-07T16:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463587#M191500</link>
      <description>&lt;P&gt;If Splunk says it sent the alert at 6AM (utc-5h) and it was recieved at 7AM(utc-5) then the delay is external to splunk.&lt;/P&gt;

&lt;P&gt;Do you have mailserver logs or a mail provider you can investigate with?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 16:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463587#M191500</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-07T16:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Searches delayed by one hour</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463588#M191501</link>
      <description>&lt;P&gt;Thank you, guys. The mail idea brought me on the right track.&lt;/P&gt;

&lt;P&gt;The email apparently sometimes gets quarantined because of its attachment and then released automatically an hour later.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 16:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-Searches-delayed-by-one-hour/m-p/463588#M191501</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2020-02-07T16:41:26Z</dc:date>
    </item>
  </channel>
</rss>

