Reporting

Changing Cron Sceheduling Saved Search

diliptmonson
Explorer

I am utilizing around 40 saved searches which runs on a CRON scheduler to populate various summary indexes. If there is an issue with underlying data, I want to stop all the saved searches and run it a different time (let's say 3 hours from the time of earlier schedule).

Is there a way in Splunk to change the timings of all scheduled searches in one go

0 Karma

hardikJsheth
Motivator

I think you can do that.

You need to enable a script execution from a particular saved search. Then from the python script you can update cron schedule for each alert.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...