Alerting

If a scheduled alert is deferred that searches between -6 and -1 minutes, will the time range be in the context of when it was run or when it should have ran?

saulverde
Path Finder

We have an alert that runs every 5 minutes. The search searches between -6 minutes and -1 minute.

When this search gets deferred, will the time frame be in the context of when it was actually run or in the context of when it should have ran?

0 Karma
1 Solution

jensonthottian
Contributor

If I understand your question correctly you have a search with relative as : -6m@m and -1m@m. If thats the case then as this is relative to time so the context is the time at which it executes.

View solution in original post

jensonthottian
Contributor

If I understand your question correctly you have a search with relative as : -6m@m and -1m@m. If thats the case then as this is relative to time so the context is the time at which it executes.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...