Other Usage

help on splunk alert slot time and cron

jip31
Motivator

hi

I try to configure my alert with an advanced slot time like this

earliest = -60m@m latest = -40m@m

But when I save, splunk tell me "The changes you have done to this alert slot time will be not saved" and "the slot time has not been updated, Change the alert type in order to modify the slot time"

what is wrong please?

And i try to use the cron below, but the cron is not taken into account

*/20****

Thanks for your help

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

where did you try to change the time period in your alert or scheduled report?

you cannot do this in Alerts (or Reports) dashboard, you have to do this in [Settings > Searches, Reports and Alerts].

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

where did you try to change the time period in your alert or scheduled report?

you cannot do this in Alerts (or Reports) dashboard, you have to do this in [Settings > Searches, Reports and Alerts].

Ciao.

Giuseppe

0 Karma

jip31
Motivator

Hi Gcusello

You are right, thanks

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...