Alerting

Cron Expression

anuj1630
New Member

Hi,
I want a cron expression for executing a query every day @ 12:45PM. The cron expression I used is : 0 45 12 * * ?. But I am getting an error stating "invalid interval, must be an integer or cron expression". Please help.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Cron strings are minute hour date month day so your example was telling Splunk to run the query at 45:00 on the 12th of every month. Try 45 12 * * *.

---
If this reply helps you, Karma would be appreciated.

hardikJsheth
Motivator

In addition to answer provided by @richgalloway, the cron schedule can't have more than five characters. For getting correct cron https://crontab.guru/ is good site.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Weird Windoze does a 6th field, which does seconds. I suspect that is the source of the incorrect cron in the question. Go with Rich's answer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...