Hello Team,
I need to send an alert on all working day at 8.00 AM with a time range of 24hrs except on Monday with a time range of 3 days. Will this be possible in our alert settings for the same SPL query but different time range. OR should we add in SPL query ?
You could append a timeframe adjustment to your base search
<your base search> [| makeresults
| fields - _time
| addinfo
| eval day=strftime(info_max_time, "%w")
| eval period=if(day == 1, "-3d", "-1d")
| eval earliest=relative_time(info_max_time,period)
| eval latest=info_max_time
| fields earliest latest]
Here I have used the end time as the reference point, but you could do similar with info_min_time
Hi @gemrose,
You can setup two alerts with below cron settings and time ranges using the same SPL;
Mondays;
Cron -> 0 8 * * 1
TimeRange --> -3d
Other days;
Cron -> 0 8 * * 2-5
TimeRange --> -24h