Hi,
I want to run a search in the time range 7AM today to 7AM the day after everyday. The servers on which my splunk is running is in GMT.
Here is my config in savedsearches.conf
cron_schedule = 02 7 * * *
dispatch.earliest_time = -1d
dispatch.latest_time = now
it runs for 12AM today till 12AM the day after. How can I change it to run from 7AM to 7AM?
Try these settings.
cron_schedule = 02 7 * * *
dispatch.earliest_time = -1d@d+7h
dispatch.latest_time = @d+7h