Alerting

Schedule alert for different time zones

hvoynova
Observer

Hello,

I have an alert which is scheduled to run at 8 AM every day using a cron expression. It checks events from different site locales.

Since this alert must be scheduled for different regions (EU, APAC, NA, etc.), is it possible to run the alert independently for each time zone? 

(example: daily alerts that run at 8AM to be able to run their checks at 8AM in each market's timezone)

Regards

 

Labels (4)
0 Karma

aashiqwork
Explorer

Create a local Splunk user called TZ_London, login as that user and set his Time zone so that Splunk knows how to interpret Timepicker values like Today and Yesterday, etc. by clicking TZ_London -> Settings -> Time zone. Then clone the report so that TZ_London owns it and it runs as him with his Time zone setting. This way Splunk handles Daylight Savings and everything else.

https://community.splunk.com/t5/Alerting/How-to-configure-alert-based-on-other-timezones/td-p/450777

Hope this helps !!!

 

Thanks

 

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...