Other Usage

What cron expression should I use to set up alert?

Deprasad
Path Finder

What is the equivalent Splunk Cron expression for the below Cron.

0 0 0 ? * 7#1 *

An alert needs to be configured for every month 1st Saturday at 00:05 AM.

Labels (2)
0 Karma

jeffland
SplunkTrust
SplunkTrust

That's not a valid cron expression.

For "every month 1st Saturday at 00:05 AM", I don't think that's possible with a single cron. You could schedule your search to run daily for a week, using this cron:

5 0 1-7 * *

And then in your search you check what day of the week it is and only return results on saturday, like this:

your existing search
| eval day_of_week = strftime(now(), "%a") | where day_of_week = "Sat"

It's not as pretty as what you brought, but it should result in your desired behavior.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...