Reporting

How to include Start Time and End Time in the message body of a scheduled email report?

skathpal
Explorer

Hello Experts,

Need help to setup the output action of Reports where in message body I can see the start and end time of report data. Let say I scheduled the report every 3 Hours via email(Output Action). In Email message body we want to see the time of the report . Start time 3 Pm and End time 6 Pm so that system owner knows its 3 hours data from 3pm to 6 pm.

Sample
Message Body

Report Name: Top 10 External IP Denied

Report Start Time: Which field ??
Report End Time : ???

Description: Displays the top 10 foreign addresses that were denied inbound access by external firewall.

Hope my question is clear.

1 Solution

vasanthmss
Motivator

Hi Skathpal,

Try This,

Report Start = $job.earliestTime$
Report End= $job.latestTime$

For more Info Read this Link

Cheers!!!

V

View solution in original post

vasanthmss
Motivator

Hi Skathpal,

Try This,

Report Start = $job.earliestTime$
Report End= $job.latestTime$

For more Info Read this Link

Cheers!!!

V

HiroshiSatoh
Champion

You can add the 「info_min_time」 and 「info_max_time」 in 「| addinfo」.

・info_min_time: the earliest time bound for the search
・info_max_time: the latest time bound for the search

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...