<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Changing Cron Sceheduling Saved Search in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Changing-Cron-Sceheduling-Saved-Search/m-p/238655#M4813</link>
    <description>&lt;P&gt;I am utilizing around 40 saved searches  which runs on a CRON scheduler to populate various summary indexes. If there is an issue with underlying data, I want to stop all the saved searches and run it a different time (let's say 3 hours from the time of earlier schedule).&lt;/P&gt;

&lt;P&gt;Is there a way in Splunk to change the timings of all scheduled searches in one go&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2016 10:27:43 GMT</pubDate>
    <dc:creator>diliptmonson</dc:creator>
    <dc:date>2016-08-17T10:27:43Z</dc:date>
    <item>
      <title>Changing Cron Sceheduling Saved Search</title>
      <link>https://community.splunk.com/t5/Reporting/Changing-Cron-Sceheduling-Saved-Search/m-p/238655#M4813</link>
      <description>&lt;P&gt;I am utilizing around 40 saved searches  which runs on a CRON scheduler to populate various summary indexes. If there is an issue with underlying data, I want to stop all the saved searches and run it a different time (let's say 3 hours from the time of earlier schedule).&lt;/P&gt;

&lt;P&gt;Is there a way in Splunk to change the timings of all scheduled searches in one go&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 10:27:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Changing-Cron-Sceheduling-Saved-Search/m-p/238655#M4813</guid>
      <dc:creator>diliptmonson</dc:creator>
      <dc:date>2016-08-17T10:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Cron Sceheduling Saved Search</title>
      <link>https://community.splunk.com/t5/Reporting/Changing-Cron-Sceheduling-Saved-Search/m-p/238656#M4814</link>
      <description>&lt;P&gt;I think you can do that. &lt;/P&gt;

&lt;P&gt;You need to enable  a script  execution from a particular saved search. Then from the python script you can update cron schedule for each alert.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 11:11:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Changing-Cron-Sceheduling-Saved-Search/m-p/238656#M4814</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2016-08-17T11:11:17Z</dc:date>
    </item>
  </channel>
</rss>

