Knowledge Management

Cron Schedule question

jacqu3sy
Path Finder

What Cron could I use to schedule a search to only run between the hours of 18:00 through until 08:00 the next day?

I'm not sure it's possible.

The idea is that a search should only run Out Of Hours, whereby an email notification will be sent to get someone out of bed, should a poisitive reuslt be found off the search.

Any ideas?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
try

0 0,1,2,3,4,5,6,7,8,18,19,20,21,22,23 * * *

Bye.
Giuseppe

View solution in original post

rbreton
Path Finder

This might be easier to read...

  • 0 18-7 * * *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
try

0 0,1,2,3,4,5,6,7,8,18,19,20,21,22,23 * * *

Bye.
Giuseppe

jacqu3sy
Path Finder

yeah that works thanks.

0 Karma

davebrooking
Contributor

Hopefully this will give you some ideas on how to do that

Dave

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...