I have not found a way to do this yet. I need to search for a message in Graylog which should appear in the log just after 6AM. I need to confirm it is there by 7AM daily with an event definition.
This the basic query to find what I am looking for:
application_name:talend-alljobs AND Done AND source:tldjobndcp* AND NewStageProductReport
I need to either find a way to just run the event definition once a day at 7 AM and look back 1 hour but have not found a way to schedule those just once a day at a specific time of day.
The other way would be to run the event definition every hour looking back 24 hours and put something in the query to make it just look between the hours of 6 and 7AM.
I have found where you can do things like this which finds it if it is withing the last 9 hours:
application_name:talend-alljobs AND Done AND source:tldjobndcp* AND NewStageProductReport AND timestamp:[now-9h TO now]
I need something like timestamp:[midnight+6h TO midnight+7h].
Any help would be appreciated.