Alerting

Set Alert Time Range to snap to yesterday at 21:00

x213217
Explorer

Hello I have an alert that runs on the Cron expression
00 2-19 * * 2-6
Starts at 2 am - runs Tuesday-Saturday and runs every hour until 19:00

My Question is for the Time range how can i set the search to always cover from the moment the search is running to 21:00 the previous day?

Tags (1)
0 Karma

dmarling
Builder

You can put this in your search or set the equivalient time on the alert under the advanced portion of the time range selector:

earliest=-1d@d+21h latest=now

If this comment/answer was helpful, please up vote it. Thank you.
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...