I already told you in https://community.splunk.com/t5/Security/Cron-Expression-for-scheduled-Alert/m-p/575364 - there's no single cron schedule that will cover all the "uneven boundaries".
How can I configure a CRON expression such that an alert was sent each 2hours in a day, and every day in weeks. ??
Many thanks !!!
HI @abazgwa21cz,
sorry but it isn't so clear:
do you want a cron expression to run alert every 2 hours in a day, an this is clear, but what do you mean with " and every day in a week"?
do you mean every 2 hours in working days (Mon-Fri) and one time in the Week end or what else?
In general, it isn't a good idea attach a new question to another one, because less people will answer you, opening a new question it's better.
Ciao.
Giuseppe
Thanks man but
*/15 8-18 * * 1-5
we are running the query evey 15min and it should took last 15min data .It means query started running at 8am it took the data from 7:45am but we need from 8am data.
Hi @jackin,
in the cron expression you can only define these parameters, you could exclude data before 8.00 in the main search (e.g. time_hours>7).
Ciao.
Giuseppe