Reporting

Time Range for a scheduled alert

bshuford
Path Finder

I'm trying to schdule an alert to report on the last month of logs.

I want the scheduled alert to report last month and snap to the month

I'm putting in under the time range section -1mon@mon

but I seem to be getting -30d

so I get the last 30 days not the last month.

Ideas?

0 Karma

msettipane
Splunk Employee
Splunk Employee

-mon@mon will snap to the beginning of the last month. Have you tried adding a latest time?

So your search would look over this time period: earliest = -mon@mon latest = @mon.

0 Karma

msettipane
Splunk Employee
Splunk Employee

You need a latest time. earliest= -mon@mon latest=@mon (this will push the latest to 12:00AM on Feb 1).

0 Karma

bshuford
Path Finder

I just did -mon@month and it gave me jan 1 - feb 4 (Today). How do I snip off the 4 days in feb?

0 Karma

bshuford
Path Finder

That was the first thing I did. I get entries from Today back a month.

0 Karma
Get Updates on the Splunk Community!

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...