I have some saved Splunk reports. I am calling these reports every hour by JAVA API call. If any hour due to some issue my query failed, I am updating that entry in table. Next hour, while running this query, i want to run for last 2 hour time range, instead of 1 hour.
Is there any way, I can control time range of saved search. I didn't have any time field in my report.
I am using Splunk Enterprise Security 7.2.5.1 .