Similar to how you can set earliest and latest in a search query to specify time constraints, you can also specify _index_earliest and _index_latest to specify time constraints based on _indextime. You would still want to schedule the search to run on the same CRON as before.
index=* _index_earliest=-60m _index_latest=now
This search will look only at events that were indexed in the past 60 minutes. Then you set your CRON to 15 * * * * to have it run every hour, fifteen minutes after the hour (or whatever interval you want).
... View more