Alerting

Schedule alert for different time zones

hvoynova
Observer

Hello,

I have an alert which is scheduled to run at 8 AM every day using a cron expression. It checks events from different site locales.

Since this alert must be scheduled for different regions (EU, APAC, NA, etc.), is it possible to run the alert independently for each time zone? 

(example: daily alerts that run at 8AM to be able to run their checks at 8AM in each market's timezone)

Regards

 

Labels (3)
0 Karma

aashiqwork
Explorer

Create a local Splunk user called TZ_London, login as that user and set his Time zone so that Splunk knows how to interpret Timepicker values like Today and Yesterday, etc. by clicking TZ_London -> Settings -> Time zone. Then clone the report so that TZ_London owns it and it runs as him with his Time zone setting. This way Splunk handles Daylight Savings and everything else.

https://community.splunk.com/t5/Alerting/How-to-configure-alert-based-on-other-timezones/td-p/450777

Hope this helps !!!

 

Thanks

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...