Alerting

If a scheduled alert is deferred that searches between -6 and -1 minutes, will the time range be in the context of when it was run or when it should have ran?

saulverde
Path Finder

We have an alert that runs every 5 minutes. The search searches between -6 minutes and -1 minute.

When this search gets deferred, will the time frame be in the context of when it was actually run or in the context of when it should have ran?

0 Karma
1 Solution

jensonthottian
Contributor

If I understand your question correctly you have a search with relative as : -6m@m and -1m@m. If thats the case then as this is relative to time so the context is the time at which it executes.

View solution in original post

jensonthottian
Contributor

If I understand your question correctly you have a search with relative as : -6m@m and -1m@m. If thats the case then as this is relative to time so the context is the time at which it executes.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...