Alerting

How can we schedule an alert with irregular times to run?

danielbb
Motivator

We have cases where we need to run an alert at 8 am on Monday and at 9 am on Tuesday, meaning, at irregular times.
Is there a way to specify such cases using the cron way or some other method?

Tags (1)
0 Karma

woodcock
Esteemed Legend

Create a super-set cron covering of all of the times and then add logic to your SPL to short-circuit your search so that it errors on those times that aren't supposed to run. See my unaccepted answer here ( UpVotes appreciated):

https://answers.splunk.com/answers/172541/is-it-possible-to-purposely-cause-a-scheduled-sear.html

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...