Reporting

How to schedule a report to run during a specific time on certain days?

cbr654
Path Finder

Hello, I setup a cron schedule to run on Tue, Wed, Thur, Fri at 8am. For example , on Tue I want to receive results showing me events from 9PM on Mon to 6AM on Tue. I am having a issue where on Wed I am still getting the same results that i received on Tue, whereas instead I should be receiving results from 9pm on Tue to 6am on Wed. muchtthanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Is the report really configured with fixed start and end times? If so, that would explain why the results are the same. Time ranges should be relative like "-11h@h" and "-2h@h".

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Is the report really configured with fixed start and end times? If so, that would explain why the results are the same. Time ranges should be relative like "-11h@h" and "-2h@h".

---
If this reply helps you, Karma would be appreciated.

cbr654
Path Finder

much thanks for assisting Rich. I am pretty amatuer with Splunk now. Yes, it was originally configured with fix start/end and i thought the cron setup will implement the date change, but I see cron is only for setting up when the report is supposed to run. I will setup the relative time in the **Advance->Earliest/Latest section? Let me see if I can get my head around setting up relative time before asking you the another question:) appreciate your help.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is the time range setting for your search?

---
If this reply helps you, Karma would be appreciated.
0 Karma

cbr654
Path Finder

Time range

Start time
1429650000

Finish time
1429682400

Cron schedule
0 8 * * 2-5

Thanks

0 Karma
Get Updates on the Splunk Community!

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...

What's New in Splunk Observability - November 2025

What's New We’re excited to announce the latest enhancements to Splunk Observability Cloud and ...

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...