Alerting

cron job not working

logloganathan
Motivator

i want to setup a alert for every hour in splunk but not at 2 am.
i used below cron expression but it not work

0 0 1 3 4 5 6 7 8 9 10 12 13 14 15 16 17 18 19 20 21 22 23 * * *

it produces a error while saving so it used expression like

0 0-1 * * *

then i created another alert and provide expression like

0 3-23 * * *

is there any other way ? please suggest.

Tags (1)
0 Karma
1 Solution

damien_chillet
Builder

Try 0 0,1,3-23 * * *

View solution in original post

0 Karma

kthammireddygar
Path Finder

I am able to Schedule with this cron job 0 0,1,3-23 * * * in Splunk Version 6.6.4.
Can you please provide a screenshot of the error (red mark at cron expression)?

logloganathan
Motivator

Thanks for your valuable response!!

0 Karma

p_gurav
Champion

Can you try :

0 0-1,3-23 * * *

logloganathan
Motivator

its not working...same result...again not able to save

0 Karma

p_gurav
Champion

Is there any error any getting?

0 Karma

logloganathan
Motivator

thanks for your valuable response

0 Karma

damien_chillet
Builder

Try 0 0,1,3-23 * * *

0 Karma

logloganathan
Motivator

its not working..not able to save

0 Karma

damien_chillet
Builder

I managed to schedule a search with with that cron on my instance...
Can you provide the error message?

0 Karma

logloganathan
Motivator

i am not able to save the alert itself

0 Karma

damien_chillet
Builder

That is strange, are you sure the cron expression is the issue?
It could be another parameter wrongly set?
Can you share a screenshot of it maybe?

0 Karma

logloganathan
Motivator

i am not able to save the file. it telling red mark at Cron expression i entered.

0 Karma

damien_chillet
Builder

Sorry to hear that...
I'm surprised we cannot get it to work.
Which version of Splunk are you running?

0 Karma

logloganathan
Motivator

its working...the mistake i did not entered the commas

so i put 0 0-1,3-23 * * * as you say earlier

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...