Changing Cron Sceheduling Saved Search


I am utilizing around 40 saved searches which runs on a CRON scheduler to populate various summary indexes. If there is an issue with underlying data, I want to stop all the saved searches and run it a different time (let's say 3 hours from the time of earlier schedule).

Is there a way in Splunk to change the timings of all scheduled searches in one go

0 Karma


I think you can do that.

You need to enable a script execution from a particular saved search. Then from the python script you can update cron schedule for each alert.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!