Reporting

How to schedule a report to run during a specific time on certain days?

cbr654
Path Finder

Hello, I setup a cron schedule to run on Tue, Wed, Thur, Fri at 8am. For example , on Tue I want to receive results showing me events from 9PM on Mon to 6AM on Tue. I am having a issue where on Wed I am still getting the same results that i received on Tue, whereas instead I should be receiving results from 9pm on Tue to 6am on Wed. muchtthanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Is the report really configured with fixed start and end times? If so, that would explain why the results are the same. Time ranges should be relative like "-11h@h" and "-2h@h".

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Is the report really configured with fixed start and end times? If so, that would explain why the results are the same. Time ranges should be relative like "-11h@h" and "-2h@h".

---
If this reply helps you, Karma would be appreciated.

cbr654
Path Finder

much thanks for assisting Rich. I am pretty amatuer with Splunk now. Yes, it was originally configured with fix start/end and i thought the cron setup will implement the date change, but I see cron is only for setting up when the report is supposed to run. I will setup the relative time in the **Advance->Earliest/Latest section? Let me see if I can get my head around setting up relative time before asking you the another question:) appreciate your help.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is the time range setting for your search?

---
If this reply helps you, Karma would be appreciated.
0 Karma

cbr654
Path Finder

Time range

Start time
1429650000

Finish time
1429682400

Cron schedule
0 8 * * 2-5

Thanks

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...