I need run the saved search every day at 8pm CST. How can I include earliest and latest in the search?
Include earliest=XXX latest=YYY in the search string.
e.g.
index=_internal sourcetype=splunkd earliest=-24h@h latest=@h
Include earliest=XXX latest=YYY in the search string.
e.g.
index=_internal sourcetype=splunkd earliest=-24h@h latest=@h
what is the value i have to keep for 8pm earliest=? latest=?
If you want to run a report at 8pm don't you need a cron schedule to handle that? The earliest and latest are the time range upon which your saved search will run. What is the requirement for your search (e.g. search should check last 24 hr data and do....)