<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Schedule search every 12 hours in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76383#M1037</link>
    <description>&lt;P&gt;I know this might seem like a simple question, but for some reason today I'm having trouble with this.&lt;/P&gt;

&lt;P&gt;I have a search.  I created an alert for this search.  I want this search to run at 7:30am and search the last 12 hours, alert if there are any results and then run again 12 hours from that time, which would be at 7:30pm.  &lt;/P&gt;

&lt;P&gt;However I'm having trouble getting this to happen.  I have this for the saved alert/search:&lt;/P&gt;

&lt;P&gt;Search:  sourcetype=TMFErrors eventtype="PlatformSQLException" ETL "No space left on device"&lt;BR /&gt;
Start Time:  -12h@h&lt;BR /&gt;
End time:  Now&lt;BR /&gt;
Schedule Type:  cron&lt;BR /&gt;
Cron Schedule:   30 7 * * *&lt;/P&gt;

&lt;P&gt;This works to have the search run at 7:30am, go back 12 hours and search for errors.  &lt;/P&gt;

&lt;P&gt;However for running again at 7:30pm, well this doesn't do it.&lt;/P&gt;

&lt;P&gt;Is there a way to do this or do I have to have 2 separate searches with alerts?  I'm assuming yes but figured I'd ask.  &lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2013 14:11:03 GMT</pubDate>
    <dc:creator>gnovak</dc:creator>
    <dc:date>2013-06-26T14:11:03Z</dc:date>
    <item>
      <title>Schedule search every 12 hours</title>
      <link>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76383#M1037</link>
      <description>&lt;P&gt;I know this might seem like a simple question, but for some reason today I'm having trouble with this.&lt;/P&gt;

&lt;P&gt;I have a search.  I created an alert for this search.  I want this search to run at 7:30am and search the last 12 hours, alert if there are any results and then run again 12 hours from that time, which would be at 7:30pm.  &lt;/P&gt;

&lt;P&gt;However I'm having trouble getting this to happen.  I have this for the saved alert/search:&lt;/P&gt;

&lt;P&gt;Search:  sourcetype=TMFErrors eventtype="PlatformSQLException" ETL "No space left on device"&lt;BR /&gt;
Start Time:  -12h@h&lt;BR /&gt;
End time:  Now&lt;BR /&gt;
Schedule Type:  cron&lt;BR /&gt;
Cron Schedule:   30 7 * * *&lt;/P&gt;

&lt;P&gt;This works to have the search run at 7:30am, go back 12 hours and search for errors.  &lt;/P&gt;

&lt;P&gt;However for running again at 7:30pm, well this doesn't do it.&lt;/P&gt;

&lt;P&gt;Is there a way to do this or do I have to have 2 separate searches with alerts?  I'm assuming yes but figured I'd ask.  &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 14:11:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76383#M1037</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-06-26T14:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Schedule search every 12 hours</title>
      <link>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76384#M1038</link>
      <description>&lt;P&gt;Your cron schedule only allows the search to run at 7:30 AM.&lt;BR /&gt;
Cron uses a 24 hour time scheme.&lt;/P&gt;

&lt;P&gt;Try setting your Cron schedule to:&lt;BR /&gt;
30 7,19 * * *&lt;/P&gt;

&lt;P&gt;This will have the search run at 0730 and again at 1930 which is 730 PM.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 14:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76384#M1038</guid>
      <dc:creator>coltadkison</dc:creator>
      <dc:date>2013-06-26T14:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Schedule search every 12 hours</title>
      <link>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76385#M1039</link>
      <description>&lt;P&gt;OMG I totally forgot about that!  Thanks you!  Crisis averted!  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 14:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Schedule-search-every-12-hours/m-p/76385#M1039</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-06-26T14:22:40Z</dc:date>
    </item>
  </channel>
</rss>

