Alerts are results of scheduled searches and those are subject to the defined cron schedule. Your cron schedule would look something like this:
*/5 19,20,21,22,23,24,01,02,03,04,06 * * *
to run the search every five minutes between the hours of 7pm and 6am.
You shall not use a real-time search, because real-time searches don't end. Pick as large of an interval as you can afford. 5 Minutes is generous for most use cases I have come across. Real-time is overrated... 😉
Alerts are results of scheduled searches and those are subject to the defined cron schedule. Your cron schedule would look something like this:
*/5 19,20,21,22,23,24,01,02,03,04,06 * * *
to run the search every five minutes between the hours of 7pm and 6am.
You shall not use a real-time search, because real-time searches don't end. Pick as large of an interval as you can afford. 5 Minutes is generous for most use cases I have come across. Real-time is overrated... 😉
Try */5 19-24,1-6 * * *
It appears that ranges have to be ascending, i.e. 19-6 doesn't work, but the above does.
*/5 19,20,21,22,23,24,01,02,03,04,05,06 * * *
is giving me an invalid cron, and I checked the format multiple times. I also tried */5 19-06 * * * and it still didn't work. I keep getting invalid cron. Any ideas?
For more information @thomashigginson on scheduled alerts and defining cron schedules, refer to the following documentation: http://docs.splunk.com/Documentation/Splunk/latest/Alert/Definescheduledalerts#Schedule_the_alert 🙂