SUGGESTION: test and Translate CRONTAB in alert

Splunk Employee
Splunk Employee

Splunk recommends as a Best Practice that real-time alerts be converted to "smallest reasonable repetition" so as to better manage resources. (real time takes a core and does not give it back). In line with that recommendation it would be helpful to make using the more granular "CRONTAB" notation easier to use by putting a bit of intelligence behind that text box.

At minimum testing the validity before allowing someone to save
At maximum, intelligently suggesting examples. (CRONTAB syntax is not likely to change without us knowing)

Resources like are wonderful - but we should at least take the bullets out of the gun.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Tags (1)


Splunk has capability of testing and translating the crontab after you save the alert .
Once saved , the cron tab is been translated and show the time in "Next Scheduled Time". Thats how I usually I validate the cron tab .

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!