- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to schedule a job to run every 25 hours in Splunk?
chandanjaisal
Explorer
11-30-2015
04:14 AM
I have a Splunk search string and I want to run this in every 25 hours.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jplumsdaine22
Influencer
11-30-2015
06:25 AM
Interesting question. I'm not sure that you can with Splunk's cron notation. If the search doesn't consume many resources, just run it every hour. Otherwise I suppose you could:
- Make a saved search
- Use cron or a bash script on a linux host to run saved/searches/{name}/dispatch http://docs.splunk.com/Documentation/Splunk/6.3.1511/RESTREF/RESTsearch#saved.2Fsearches.2F.7Bname.7...
Check out http://stackoverflow.com/questions/1417098/cronjob-every-25-hours
I'm curious: what use case do you have for this search?
