Alerting

Alert To Email | Cron Job | 9 AM to Now

geekf
Path Finder

I am running a search with a corn expression "0 10-18/2 * * *". This translates to "At minute 0 past every 2nd hour from 10 through 18.

I want to run this job every time with "9 AM to Now", and there isn't an option under "Time Range". I would appreciate if someone can help me achieve this.

Labels (4)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Add earliest=@d+9h to the query (before the first pipe).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Add earliest=@d+9h to the query (before the first pipe).

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...