Reporting

set savedsearch schedule

kind7776
New Member

Hi,

I am using Splunk Enterprise Version 6.6.6v.

Can I set the schedule setting in seconds during savedsearch configuration?

Thanks.

Tags (1)
0 Karma

woodcock
Esteemed Legend

No, the minimum granularity is minutes.

0 Karma

kind7776
New Member

Is there any evidence that this is not true?

0 Karma

xpac
SplunkTrust
SplunkTrust

Check the corresponding doc:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Savedsearchesconf

It does not explicitly state seconds are impossible, but it states the format for crown schedules and therefore what is possible.

0 Karma

ssadanala1
Contributor

Its not possible using cron scheduler because splunk considers cron format and the least time modifier in cron format is minutes .

Another work around is specifying * * * * * so that the it keeps running or setting the alert time to real time

Happy splunking !!

0 Karma

kind7776
New Member

Is there any evidence that this is not true?

0 Karma

ssadanala1
Contributor

The only evidence I can say is referring to https://crontab.guru/

You can find about the time modifiers supported by a cron scheduler .

Happy Splunking !!

0 Karma

kind7776
New Member

Thanks!

If so, is it impossible to set the seconds in Splunk in any other way?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...