Reporting
Highlighted

Schedule an alert

Contributor

How to schedule an alert to search for last hour data.
Ex: I have to schedule Alert to search for 9:00am-10:00am data. My Alert is scheduled at 15th min of every hour(15 */1 * * *). At 10:15 am, My alert runs, But I need it to search for last hour data(9-10am). what should be the earliest and the latest time settings?

0 Karma
Highlighted

Re: Schedule an alert

SplunkTrust
SplunkTrust

Go to Save As in the upper right corner after you have a search in the search bar and select Alert

There will be 2 fields Earliest and Latest

The Earliest field should have -1h@h
The Latest field should have now

This will set a 1 hour window of the previous hour

You will also see the timeranges populate once you enter in those values

0 Karma
Highlighted

Re: Schedule an alert

Contributor

If I use latest time as now, then it will search for the data from 9:00-10:15 right? I just need 1 hr data

0 Karma
Highlighted

Re: Schedule an alert

Splunk Employee
Splunk Employee

Just use earliest=-1h@h latest=@h to search from 9-10 (assuming a 10:15/30/45 search run time.
Details here

0 Karma
Highlighted

Re: Schedule an alert

SplunkTrust
SplunkTrust

Use earliest as -1h@h and latest as @h

0 Karma