Reporting

Time Range for a scheduled alert

bshuford
Path Finder

I'm trying to schdule an alert to report on the last month of logs.

I want the scheduled alert to report last month and snap to the month

I'm putting in under the time range section -1mon@mon

but I seem to be getting -30d

so I get the last 30 days not the last month.

Ideas?

0 Karma

msettipane
Splunk Employee
Splunk Employee

-mon@mon will snap to the beginning of the last month. Have you tried adding a latest time?

So your search would look over this time period: earliest = -mon@mon latest = @mon.

0 Karma

msettipane
Splunk Employee
Splunk Employee

You need a latest time. earliest= -mon@mon latest=@mon (this will push the latest to 12:00AM on Feb 1).

0 Karma

bshuford
Path Finder

I just did -mon@month and it gave me jan 1 - feb 4 (Today). How do I snip off the 4 days in feb?

0 Karma

bshuford
Path Finder

That was the first thing I did. I get entries from Today back a month.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...