I am fairly new to Splunk Enterprise and I read the documentation about writing cron expressions. Does Splunk support special characters when you are writing cron expressions?
Example of special characters: * , - ? L W
Example cron syntax: 0 */2 * ? * *
I've just tested - splunk cron doesn't accept any special cron characters, except listed on the doc page (*,-/)
https://docs.splunk.com/Documentation/Splunk/latest/Alert/CronExpressions
https://en.wikipedia.org/wiki/Cron#CRON_expression
yes , you can use these characters without L
W
C
But I've never tried it, so please give it a try and let me know how you do it.