Alerting

Why is my alert not running?

ASISH_9
Engager

I scheduled a search Alert with cron expression="48 11 * * 1-5",Although in search it is working fine but it is not working as an alert.Is there any problem with my search query or Alert configuration?Please suggest

Tags (1)
0 Karma
1 Solution

DanielASG
Explorer

this Cron expression does not look right

how often did you want this to run

for every 15min use

0 0/15 * 1/1 * ? *

View solution in original post

kmaron
Motivator

It looks like your Cron schedule is off

Splunk has some really great documentation on how to format your Cron schedule:
http://docs.splunk.com/Documentation/Splunk/6.5.2/Alert/Definescheduledalerts#Using_cron_expressions

0 Karma

DanielASG
Explorer

this Cron expression does not look right

how often did you want this to run

for every 15min use

0 0/15 * 1/1 * ? *
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...