Alerting

Adding running time in the query

Kwip
Contributor

I need to set up alert for one of my query.
I will be setting it to run for every 1 hour. But when its running on every one hour i want the run to be start from yesterday 14:00
Say example,
04/04/2017 10:00 - Run from 04/03/2017 14:00 to 04/04/2017 10:00
04/04/2017 11:00 - Run from 04/03/2017 14:00 to 04/04/2017 11:00
04/04/2017 12:00 - Run from 04/03/2017 14:00 to 04/04/2017 12:00
04/04/2017 13:00 - Run from 04/03/2017 14:00 to 04/04/2017 13:00

Thanks in advance

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try earliest=-1d@d+14h

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Try earliest=-1d@d+14h

---
If this reply helps you, Karma would be appreciated.

DalJeanis
Legend

And you'd probably be better off delaying the run for a few minutes to make sure all the indexing has been done for the hour you are just checking. For example, run at 10:10 for yesterday 14:00 through today 10:00.

earliest=-1d@d+14h latest=@h

Kwip
Contributor

Hello Daljeanis,
Sorry for the question on old post. I will create new question if you required.

earliest=-1d@d+14h latest=@h ==> this one will is working fine, if i am searching the yesterday's information on today. what if I need to search the same day.

I want to monitor my dashboard from today 7 Am to tomorrow 5 AM. I don't want to set the time manually.

FYI, My dashboard contains list of jobs running from 7AM to next day 5AM.

I need to monitor the progress continuously, so set up the auto refresh on every 5 minutes. Now I want to set the time in such a way that it will take the start time as 7AM today and end time is now or next day 5AM during every refresh.

Please take a look and let me know the possibilities. Thanks in advance!!!

0 Karma

Kwip
Contributor

That works!!! Thank you!!

0 Karma

Kwip
Contributor

Created new question for this

"Setting the query start time and end time"

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...