What is the equivalent Splunk Cron expression for the below Cron.
0 0 0 ? * 7#1 *
An alert needs to be configured for every month 1st Saturday at 00:05 AM.
That's not a valid cron expression.
For "every month 1st Saturday at 00:05 AM", I don't think that's possible with a single cron. You could schedule your search to run daily for a week, using this cron:
5 0 1-7 * *And then in your search you check what day of the week it is and only return results on saturday, like this:
your existing search
| eval day_of_week = strftime(now(), "%a") | where day_of_week = "Sat"It's not as pretty as what you brought, but it should result in your desired behavior.