<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why the alert did not trigger for below cron expression? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413973#M11325</link>
    <description>&lt;P&gt;And before @mattymo says, it: Meta W00t!&lt;/P&gt;</description>
    <pubDate>Sat, 30 Jun 2018 03:30:20 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2018-06-30T03:30:20Z</dc:date>
    <item>
      <title>Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413965#M11317</link>
      <description>&lt;P&gt;16-59/10 5-6 * * *  cron was setup for more than 0 events.&lt;/P&gt;

&lt;P&gt;We had an event at 5:15 Am. Any idea why the alert did not trigger?&lt;/P&gt;

&lt;P&gt;The query used is for -5m@m&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 10:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413965#M11317</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2018-06-29T10:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413966#M11318</link>
      <description>&lt;P&gt;With that cron schedule, I guess the search ran first time at 5:20 AM? Did you confirm the search actually ran, and indeed ran at that time?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 10:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413966#M11318</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-29T10:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413967#M11319</link>
      <description>&lt;P&gt;@FrankVI&lt;BR /&gt;
Should not the search run at 5:16 and check for last 5 minutes? Also, how to check when the search ran at that time?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 10:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413967#M11319</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2018-06-29T10:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413968#M11320</link>
      <description>&lt;P&gt;No, you set it to /10, so it runs at 0,10,20,30,40,50 (where 0 and 10 are skipped because of your 16-59 time window).&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 10:58:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413968#M11320</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-29T10:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413969#M11321</link>
      <description>&lt;P&gt;I just checked and confirmed that the it is scheduled  05:16:00 &lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 11:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413969#M11321</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2018-06-29T11:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413970#M11322</link>
      <description>&lt;P&gt;According to me,cron expression =   16-59/10 5-6 * * * means the search query will trigger at 5 hours and between 16 to 59 minutes in a span of 10 minutes, same for the hour 6.&lt;/P&gt;

&lt;P&gt;So it will run,&lt;/P&gt;

&lt;P&gt;5:16, 5:26, 5:36, 5:46, 5:56 and same for 6th hour&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 11:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413970#M11322</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2018-06-29T11:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413971#M11323</link>
      <description>&lt;P&gt;Hmm, I might be wrong about that then. I also checked with crontab guru and that agrees with you that it would run at 16,26,36,46,56 : &lt;A href="https://crontab.guru/#16-59/10_5-6_*_*_*"&gt;https://crontab.guru/#16-59/10_5-6_*_*_*&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Note: I added 2 stars at the end to make it a proper complete cron schedule.&lt;/P&gt;

&lt;P&gt;From the settings page for saved searches, you should see a "View Recent" link in the actions column. Which allows you to inspect recent search executions. Also saved search executions are logged in index=_audit.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 11:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413971#M11323</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-29T11:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413972#M11324</link>
      <description>&lt;P&gt;Just because your event happened at that time does not mean that it was indexed and searchable at the time the search ran.  A window so short as "within the last 5 minutes" leaves very little time for pipeline latencies which are common forwarding events into Splunk.  If you compare the value of &lt;CODE&gt;_time&lt;/CODE&gt; with &lt;CODE&gt;_indextime&lt;/CODE&gt; for that event and they are more than 5-minutes apart (300 seconds), then the latency indicates that the event was not searchable in Splunk when the search looking for it ran.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jun 2018 03:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413972#M11324</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-06-30T03:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why the alert did not trigger for below cron expression?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413973#M11325</link>
      <description>&lt;P&gt;And before @mattymo says, it: Meta W00t!&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jun 2018 03:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-the-alert-did-not-trigger-for-below-cron-expression/m-p/413973#M11325</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-06-30T03:30:20Z</dc:date>
    </item>
  </channel>
</rss>

