<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cron expressions not to trigger alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508305#M9282</link>
    <description>&lt;P&gt;cron does not have a concept of "not".&amp;nbsp; It only specifies run times, not don't-run times.&amp;nbsp; If you can't craft a cron expression that excludes undesired times, then consider multiple searches with cron schedules that combine to cover the desired times.&amp;nbsp; For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;0/10 0 * * * # Every 10 minutes during hour 0 

15-59/10 1,2 * * * # Every 10 minutes starting at x:15 during hours 1 and 2

0/10 3-23 * * * # Every 10 minutes for the remainder of the day&lt;/LI-CODE&gt;&lt;P&gt;I use&amp;nbsp;&lt;A href="https://crontab.guru/" target="_blank"&gt;https://crontab.guru/&lt;/A&gt;&amp;nbsp;to test my cron strings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2020 13:55:10 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-07-09T13:55:10Z</dc:date>
    <item>
      <title>Splunk Cron expressions not to trigger alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508303#M9281</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am looking for a cron expression &lt;STRONG&gt;NOT&lt;/STRONG&gt; to trigger alert for a particular period of time on daily basis. Alert is scheduled to run for every 10 minutes.&lt;/P&gt;&lt;P&gt;1:00 AM to 1:15 AM&lt;/P&gt;&lt;P&gt;2:00 AM to 2:15 AM&lt;/P&gt;&lt;P&gt;Kindly help me.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 13:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508303#M9281</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2020-07-09T13:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cron expressions not to trigger alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508305#M9282</link>
      <description>&lt;P&gt;cron does not have a concept of "not".&amp;nbsp; It only specifies run times, not don't-run times.&amp;nbsp; If you can't craft a cron expression that excludes undesired times, then consider multiple searches with cron schedules that combine to cover the desired times.&amp;nbsp; For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;0/10 0 * * * # Every 10 minutes during hour 0 

15-59/10 1,2 * * * # Every 10 minutes starting at x:15 during hours 1 and 2

0/10 3-23 * * * # Every 10 minutes for the remainder of the day&lt;/LI-CODE&gt;&lt;P&gt;I use&amp;nbsp;&lt;A href="https://crontab.guru/" target="_blank"&gt;https://crontab.guru/&lt;/A&gt;&amp;nbsp;to test my cron strings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 13:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508305#M9282</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-09T13:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cron expressions not to trigger alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508320#M9283</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;i will check this in testing alert and let you know the updates&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 14:30:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/508320#M9283</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2020-07-09T14:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cron expressions not to trigger alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/509834#M9328</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;Thanks for the quick solution it worked good&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 13:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/509834#M9328</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2020-07-18T13:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cron expressions not to trigger alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/510642#M9346</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; - Can i get cron expression for the alerts not to trigger on sunday from 12 AM - 8 AM alone?&lt;/P&gt;&lt;P&gt;i tried below but the alerts for remaining days it's not getting triggered as the cron expression is specifically for Sunday alone to not trigger from 12 AM - 8 AM.&lt;/P&gt;&lt;P&gt;10-59/10 08 * * 7&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 12:40:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/510642#M9346</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2020-07-23T12:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cron expressions not to trigger alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/510666#M9348</link>
      <description>&lt;P&gt;As I said in my original reply,&amp;nbsp;&lt;SPAN&gt;cron does not have a concept of "not".&amp;nbsp; It only specifies run times, not don't-run times.&amp;nbsp; If you can't describe the schedule in a single cron then you may need multiple instances of the alert with different cron expressions.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;10-59/10 8-23 * * 7
10-59/10 * * * 1-6&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 23 Jul 2020 13:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cron-expressions-not-to-trigger-alert/m-p/510666#M9348</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-23T13:52:27Z</dc:date>
    </item>
  </channel>
</rss>

