Knowledge Management

Cron Schedule question

jacqu3sy
Path Finder

What Cron could I use to schedule a search to only run between the hours of 18:00 through until 08:00 the next day?

I'm not sure it's possible.

The idea is that a search should only run Out Of Hours, whereby an email notification will be sent to get someone out of bed, should a poisitive reuslt be found off the search.

Any ideas?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
try

0 0,1,2,3,4,5,6,7,8,18,19,20,21,22,23 * * *

Bye.
Giuseppe

View solution in original post

rbreton
Path Finder

This might be easier to read...

  • 0 18-7 * * *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
try

0 0,1,2,3,4,5,6,7,8,18,19,20,21,22,23 * * *

Bye.
Giuseppe

jacqu3sy
Path Finder

yeah that works thanks.

0 Karma

davebrooking
Contributor

Hopefully this will give you some ideas on how to do that

Dave

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...