Alerting

cron job not working

logloganathan
Motivator

i want to setup a alert for every hour in splunk but not at 2 am.
i used below cron expression but it not work

0 0 1 3 4 5 6 7 8 9 10 12 13 14 15 16 17 18 19 20 21 22 23 * * *

it produces a error while saving so it used expression like

0 0-1 * * *

then i created another alert and provide expression like

0 3-23 * * *

is there any other way ? please suggest.

Tags (1)
0 Karma
1 Solution

damien_chillet
Builder

Try 0 0,1,3-23 * * *

View solution in original post

0 Karma

kthammireddygar
Path Finder

I am able to Schedule with this cron job 0 0,1,3-23 * * * in Splunk Version 6.6.4.
Can you please provide a screenshot of the error (red mark at cron expression)?

logloganathan
Motivator

Thanks for your valuable response!!

0 Karma

p_gurav
Champion

Can you try :

0 0-1,3-23 * * *

logloganathan
Motivator

its not working...same result...again not able to save

0 Karma

p_gurav
Champion

Is there any error any getting?

0 Karma

logloganathan
Motivator

thanks for your valuable response

0 Karma

damien_chillet
Builder

Try 0 0,1,3-23 * * *

0 Karma

logloganathan
Motivator

its not working..not able to save

0 Karma

damien_chillet
Builder

I managed to schedule a search with with that cron on my instance...
Can you provide the error message?

0 Karma

logloganathan
Motivator

i am not able to save the alert itself

0 Karma

damien_chillet
Builder

That is strange, are you sure the cron expression is the issue?
It could be another parameter wrongly set?
Can you share a screenshot of it maybe?

0 Karma

logloganathan
Motivator

i am not able to save the file. it telling red mark at Cron expression i entered.

0 Karma

damien_chillet
Builder

Sorry to hear that...
I'm surprised we cannot get it to work.
Which version of Splunk are you running?

0 Karma

logloganathan
Motivator

its working...the mistake i did not entered the commas

so i put 0 0-1,3-23 * * * as you say earlier

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...