Alerting

SUGGESTION: test and Translate CRONTAB in alert

rsennett_splunk
Splunk Employee
Splunk Employee

Splunk recommends as a Best Practice that real-time alerts be converted to "smallest reasonable repetition" so as to better manage resources. (real time takes a core and does not give it back). In line with that recommendation it would be helpful to make using the more granular "CRONTAB" notation easier to use by putting a bit of intelligence behind that text box.

At minimum testing the validity before allowing someone to save
At maximum, intelligently suggesting examples. (CRONTAB syntax is not likely to change without us knowing)

Resources like https://crontabguru.com are wonderful - but we should at least take the bullets out of the gun.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Tags (1)

ssadanala1
Contributor

Splunk has capability of testing and translating the crontab after you save the alert .
Once saved , the cron tab is been translated and show the time in "Next Scheduled Time". Thats how I usually I validate the cron tab .

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...