Alerting

How can I configure an alert every 10 minutes with a delay?

adzg
Engager

I need to make sure that a file is delivered every 10 minutes.  It always arrives 5 seconds after the top of the 10 min mark (6:00:05, 6:10:05... 6:50:05, 7:00:05 etc.)  between 6am-3pm on weekdays.  

This is the closest thing I've been able to come up with

 

*/11 6-15 * * 1-5

 

I can't use */10 because the file arrives 5 seconds after the 10 minute marks, so I used 11 and set the time range as 5 minutes so that last run of the hour catches the XX:50:05 file.  The problem is that this solution always misses the first file that arrives at the top of the hour (XX:00:05) since it runs every 11 minutes.   For whatever reason, at the beginning of each hour it runs immediately but then misses the first file since the file arrives 5 seconds later. 

Can anyone think of a better solution or do I just have to create a second alert for those top-of-the-hour files? I can't seem to find a way to delay the search by a few seconds.  And how can I mute the erroneous triggers from the first alert?

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The cron form */11 says to run at minute zero and every 11 minutes until minute 59.  To run at minute 1 and every 10 minutes after that, use this expression.

1,11,21,31,41,51 6-15 * * 1-5
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The cron form */11 says to run at minute zero and every 11 minutes until minute 59.  To run at minute 1 and every 10 minutes after that, use this expression.

1,11,21,31,41,51 6-15 * * 1-5
---
If this reply helps you, Karma would be appreciated.

somesoni2
Revered Legend

Try this

 

1-59/11 6-15 * * 1-5

 

At every 11th minute from 1 through 59 past every hour from 6 through 15 on every day-of-week from Monday through Friday.
next at 2022-01-05 06:01:00
then at 2022-01-05 06:12:00
then at 2022-01-05 06:23:00
then at 2022-01-05 06:34:00
then at 2022-01-05 06:45:00
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...