Alerting

Schedule alert for different time zones

hvoynova
Observer

Hello,

I have an alert which is scheduled to run at 8 AM every day using a cron expression. It checks events from different site locales.

Since this alert must be scheduled for different regions (EU, APAC, NA, etc.), is it possible to run the alert independently for each time zone? 

(example: daily alerts that run at 8AM to be able to run their checks at 8AM in each market's timezone)

Regards

 

Labels (3)
0 Karma

aashiqwork
Explorer

Create a local Splunk user called TZ_London, login as that user and set his Time zone so that Splunk knows how to interpret Timepicker values like Today and Yesterday, etc. by clicking TZ_London -> Settings -> Time zone. Then clone the report so that TZ_London owns it and it runs as him with his Time zone setting. This way Splunk handles Daylight Savings and everything else.

https://community.splunk.com/t5/Alerting/How-to-configure-alert-based-on-other-timezones/td-p/450777

Hope this helps !!!

 

Thanks

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...