Reporting

How to schedule a report to run during a specific time on certain days?

cbr654
Path Finder

Hello, I setup a cron schedule to run on Tue, Wed, Thur, Fri at 8am. For example , on Tue I want to receive results showing me events from 9PM on Mon to 6AM on Tue. I am having a issue where on Wed I am still getting the same results that i received on Tue, whereas instead I should be receiving results from 9pm on Tue to 6am on Wed. muchtthanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Is the report really configured with fixed start and end times? If so, that would explain why the results are the same. Time ranges should be relative like "-11h@h" and "-2h@h".

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Is the report really configured with fixed start and end times? If so, that would explain why the results are the same. Time ranges should be relative like "-11h@h" and "-2h@h".

---
If this reply helps you, Karma would be appreciated.

cbr654
Path Finder

much thanks for assisting Rich. I am pretty amatuer with Splunk now. Yes, it was originally configured with fix start/end and i thought the cron setup will implement the date change, but I see cron is only for setting up when the report is supposed to run. I will setup the relative time in the **Advance->Earliest/Latest section? Let me see if I can get my head around setting up relative time before asking you the another question:) appreciate your help.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is the time range setting for your search?

---
If this reply helps you, Karma would be appreciated.
0 Karma

cbr654
Path Finder

Time range

Start time
1429650000

Finish time
1429682400

Cron schedule
0 8 * * 2-5

Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...