Concerning the subtleties of _index_time in search, making sure you find the events you need, great conf talk on this https://conf.splunk.com/watch/conf-online.html?search=PLA1327B&search.event=conf21 slides directly https://conf.splunk.com/files/2021/slides/PLA1327B.pdf >With minimal up-front effort it is possible to guarantee that your alerts and other scheduled searches run, are always successful, and do not miss data. Common challenges are skipped searches, latent data, Splunk down time, failures, and dependencies on other searches. Approaches such as an expanded sliding window consume additional resources and will inevitably fail. We will demonstrate a Splunk macro that tracks search execution times in a KVstore and dynamically controls the search timeframe, thus decoupling it from execution time. This additionally provides a capability to quickly and easily re-run a search over any timeframe in a controllable manner. We will further demonstrate the use of Apache Airflow for more complex use cases.
... View more