Alerting

Required a cron expression

sureshkumaar
Path Finder

Required a single cron expression for alerts to trigger from 12 AM to 1:30 AM and 2:30 AM to rest of the day.

Kindly help

Labels (1)
0 Karma

to4kawa
Ultra Champion

Are you confused with the search period?

0 Karma

sureshkumaar
Path Finder

Actually i am not confused, the requirement is not to trigger alerts with events showing time between 1:30 AM - 2:00 AM on daily basis.

Based upon this requirement i was looking for a cron expression

0 Karma

to4kawa
Ultra Champion

@sureshkumaar 

It's a CRON to do a search at a certain time.
Do you search at one-minute intervals?
I'm asking because you haven't offered those conditions at all?

0 Karma

sureshkumaar
Path Finder

Hi @to4kawa 

I am using search at 20 minute interval

0 Karma

sureshkumaar
Path Finder

Hi @to4kawa - Can you update is there any way to have a cron expression for this requirement

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...