Splunk Enterprise Security

How to control Report time range

twh1
Communicator

I have some saved Splunk reports. I am calling these reports every hour by JAVA API call. If any hour due to some issue my query failed, I am updating that entry in table. Next hour, while running this query, i want to run for last 2 hour time range, instead of 1 hour.

Is there any way, I can control time range of saved search. I didn't have any time field in my report.

I am using Splunk Enterprise Security 7.2.5.1 .

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...