Knowledge Management

Cron Schedule question

jacqu3sy
Path Finder

What Cron could I use to schedule a search to only run between the hours of 18:00 through until 08:00 the next day?

I'm not sure it's possible.

The idea is that a search should only run Out Of Hours, whereby an email notification will be sent to get someone out of bed, should a poisitive reuslt be found off the search.

Any ideas?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
try

0 0,1,2,3,4,5,6,7,8,18,19,20,21,22,23 * * *

Bye.
Giuseppe

View solution in original post

rbreton
Path Finder

This might be easier to read...

  • 0 18-7 * * *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
try

0 0,1,2,3,4,5,6,7,8,18,19,20,21,22,23 * * *

Bye.
Giuseppe

jacqu3sy
Path Finder

yeah that works thanks.

0 Karma

davebrooking
Contributor

Hopefully this will give you some ideas on how to do that

Dave

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...