How to schedule a job to run every 25 hours in Splunk?


I have a Splunk search string and I want to run this in every 25 hours.

Tags (2)
0 Karma


Interesting question. I'm not sure that you can with Splunk's cron notation. If the search doesn't consume many resources, just run it every hour. Otherwise I suppose you could:

  1. Make a saved search
  2. Use cron or a bash script on a linux host to run saved/searches/{name}/dispatch

Check out

I'm curious: what use case do you have for this search?

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!