Splunk Cron expression for
Everyone day 6 a.m to 6 p.m in every one hour And except Saturday 2 a.m to 8 a.m.
i think we can not have this two conditions for the hour field itself.. so we have to write two cronjobs.
* * * * * Script
MIN HOUR DayOfMonth MON DayOfWeek Script
First cron - Every day 6 a.m to 6 p.m in every one hour
* 6-18 * * * Script
Second cron - Except Saturday 2 a.m to 8 a.m. --- run only on saturday at 0, 1, 9 to 23hrs
* 0-1 9-23 * * 6 Script
Please test it throughly before implementing it on prod.
if it helped you, pls upvote.