<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled Alert using crontab shows next run time inconsistent with timezone on the Search Head in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Scheduled-Alert-using-crontab-shows-next-run-time-inconsistent/m-p/604693#M14006</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228233"&gt;@justinhaynes&lt;/a&gt;&amp;nbsp;- As per my understanding.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If the scheduled alert is configured with a specific user, it uses the user's configured timezone.&lt;/LI&gt;&lt;LI&gt;If the scheduled alert shows "nobody" as the username then it uses Search Head's timezone as default as described by the doc.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please kindly check if you have set the alert then your configured timezone is what you are observing (EDT).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jul 2022 05:12:26 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-07-07T05:12:26Z</dc:date>
    <item>
      <title>Scheduled Alert using crontab shows next run time inconsistent with timezone on the Search Head</title>
      <link>https://community.splunk.com/t5/Alerting/Scheduled-Alert-using-crontab-shows-next-run-time-inconsistent/m-p/604690#M14005</link>
      <description>&lt;P&gt;I scheduled a search to run at 0 2,8,14,20 * * *&amp;nbsp;&lt;/P&gt;&lt;P&gt;The timezone of the search head is UTC.&amp;nbsp; Therefore I expect the next run tiem to be 2am UTC, yet Splunk says the next run time would be 6am UTC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How could this be? And where is this configured?&lt;/P&gt;&lt;P&gt;I suspect there is a setting somewhere which is making the cron expressions be interpreted in US Eastern Time. Since we are observing Daylight Savings Time, Eastern Daylight Time would be UTC-4.&lt;/P&gt;&lt;P&gt;The documentation (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/CronExpressions" target="_blank" rel="noopener"&gt;Use cron expressions for alert scheduling - Splunk Documentation&lt;/A&gt;) says "&lt;SPAN&gt;The Splunk cron analyzer defaults to the timezone where the search head is configured. This can be verified or changed by going to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Settings &amp;gt; Searches, reports, and alerts &amp;gt; Scheduled time&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;I find no "Scheduled Time" under Settings &amp;gt; Search, reports and alerts.&lt;/P&gt;&lt;P&gt;I did post this to the feedback on that documentation page in case it is actually inaccurate.&lt;/P&gt;&lt;P&gt;Where can I check and verify?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 02:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scheduled-Alert-using-crontab-shows-next-run-time-inconsistent/m-p/604690#M14005</guid>
      <dc:creator>justinhaynes</dc:creator>
      <dc:date>2022-07-07T02:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Alert using crontab shows next run time inconsistent with timezone on the Search Head</title>
      <link>https://community.splunk.com/t5/Alerting/Scheduled-Alert-using-crontab-shows-next-run-time-inconsistent/m-p/604693#M14006</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228233"&gt;@justinhaynes&lt;/a&gt;&amp;nbsp;- As per my understanding.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If the scheduled alert is configured with a specific user, it uses the user's configured timezone.&lt;/LI&gt;&lt;LI&gt;If the scheduled alert shows "nobody" as the username then it uses Search Head's timezone as default as described by the doc.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please kindly check if you have set the alert then your configured timezone is what you are observing (EDT).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 05:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scheduled-Alert-using-crontab-shows-next-run-time-inconsistent/m-p/604693#M14006</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-07-07T05:12:26Z</dc:date>
    </item>
  </channel>
</rss>

