<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Execute an alert based on crontab expression in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538664#M10200</link>
    <description>&lt;P&gt;Thanks all for your help,&lt;/P&gt;&lt;P&gt;my first input seemed to work also but i did not have certain permissions while creating the alert.&lt;/P&gt;&lt;P&gt;Now it is correct and i got the alert at 12h30 and expecting the next one at 14h30.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Feb 2021 18:53:33 GMT</pubDate>
    <dc:creator>zony2021</dc:creator>
    <dc:date>2021-02-04T18:53:33Z</dc:date>
    <item>
      <title>Execute an alert based on crontab expression</title>
      <link>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538637#M10196</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;i need to execute an alert each 2hours from 8AM to 11PM.&lt;/P&gt;&lt;P&gt;I would like the alert to be scheduled 30mn after.&lt;/P&gt;&lt;P&gt;Ex:8h30 10h30 12h30 14h30 16h30 18h30 20h30 22h30.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;PS: i tried&amp;nbsp;30 8,10,12,14,16,18,20,23 * * * but it does not seem to work well.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 16:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538637#M10196</guid>
      <dc:creator>zony2021</dc:creator>
      <dc:date>2021-02-04T16:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Execute an alert based on crontab expression</title>
      <link>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538642#M10197</link>
      <description>&lt;P&gt;Hi. Other than the typo above where you had 23 instead of 22 that cron schedule syntax looks correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is happening exactly for this alert?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could look in the_internal log for the savedsearch_name= and see if the alert is firing.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 16:20:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538642#M10197</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-02-04T16:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Execute an alert based on crontab expression</title>
      <link>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538645#M10199</link>
      <description>&lt;P&gt;Try to shorten crontab like this:&lt;BR /&gt;30 8-22/2 * * *&lt;BR /&gt;&lt;BR /&gt;Other than that, make sure you have a privilege to see alert and test alert SPL in search to make sure its retrieving any number of results, since if it is not you wont get alert.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 16:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538645#M10199</guid>
      <dc:creator>me74fhfd</dc:creator>
      <dc:date>2021-02-04T16:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Execute an alert based on crontab expression</title>
      <link>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538664#M10200</link>
      <description>&lt;P&gt;Thanks all for your help,&lt;/P&gt;&lt;P&gt;my first input seemed to work also but i did not have certain permissions while creating the alert.&lt;/P&gt;&lt;P&gt;Now it is correct and i got the alert at 12h30 and expecting the next one at 14h30.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 18:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Execute-an-alert-based-on-crontab-expression/m-p/538664#M10200</guid>
      <dc:creator>zony2021</dc:creator>
      <dc:date>2021-02-04T18:53:33Z</dc:date>
    </item>
  </channel>
</rss>

