Reporting

How to schedule a job to run every 25 hours in Splunk?

chandanjaisal
Explorer

I have a Splunk search string and I want to run this in every 25 hours.

Tags (2)
0 Karma

jplumsdaine22
Influencer

Interesting question. I'm not sure that you can with Splunk's cron notation. If the search doesn't consume many resources, just run it every hour. Otherwise I suppose you could:

  1. Make a saved search
  2. Use cron or a bash script on a linux host to run saved/searches/{name}/dispatch http://docs.splunk.com/Documentation/Splunk/6.3.1511/RESTREF/RESTsearch#saved.2Fsearches.2F.7Bname.7...

Check out http://stackoverflow.com/questions/1417098/cronjob-every-25-hours

I'm curious: what use case do you have for this search?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...