Reporting

Why does scheduled report restricts the event time to the last 24 hours?

blablabla
Path Finder

Hello,

I am using a scheduled report to fill a summary index. The report is supposed to work with indextime and process everything, that came new within the last hour.
Therefore I configured the timerange the following way:

blablabla_0-1649773888778.png

But somehow the scheduled report restricts the event time to the last 24 hours, which can yield to no search results in a case, that indexed data is from the day before yesterday:

blablabla_1-1649773947909.png

Does someone know, why this restriction is happening, although the event time is supposed to be unrestricted?

Thanks and best regards

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...