<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert scheduler question in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617831#M214712</link>
    <description>&lt;P&gt;You can try scheduling it as a real time search which causes it to run continously and process data as it comes in.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 12:41:31 GMT</pubDate>
    <dc:creator>johnhuang</dc:creator>
    <dc:date>2022-10-20T12:41:31Z</dc:date>
    <item>
      <title>Alert scheduler question- How to run in seconds?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617822#M214704</link>
      <description>&lt;P&gt;Good afternoon! I figured out how to set up alerts. Understood with the parameter: Cron Expression.&lt;/P&gt;
&lt;P&gt;Currently I am using: */1 * * * * (run every minute).&lt;/P&gt;
&lt;P&gt;Tell me how to run in seconds, I tried a lot of options, but the splunk swears - it gives an error. How, for example, to run every 30 or 40 seconds?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 14:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617822#M214704</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-10-20T14:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alert scheduler question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617828#M214709</link>
      <description>&lt;P&gt;Cron jobs do not support seconds -- I'm not sure why you need to run something this frequent?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617828#M214709</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-20T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Alert scheduler question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617830#M214711</link>
      <description>&lt;P&gt;Understood thanks!&lt;BR /&gt;Well, how to say, for demos and testing, such intervals are convenient.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617830#M214711</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-10-20T12:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Alert scheduler question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617831#M214712</link>
      <description>&lt;P&gt;You can try scheduling it as a real time search which causes it to run continously and process data as it comes in.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-scheduler-question-How-to-run-in-seconds/m-p/617831#M214712</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-20T12:41:31Z</dc:date>
    </item>
  </channel>
</rss>

