Splunk Enterprise Security

How is the cron_schedule_map lookup in the SA-Utils app of Splunk Enterprise Security used?

jdeer0618
Explorer

There is a lookup in the SA-Utils app called "cron_schedule_map.csv" and I was wondering if any one out there knows how it is leveraged in ES. Attached is what the first few rows look like.

Thanks,
JD

alt text

0 Karma
1 Solution

LukeMurphey
Champion

This lookup exists only to provide information as to when searches run. It isn't really used for anything in the app (i.e. isn't used to drive scripts or searches).

The main reason it exists is to help people who are writing searches to find times that not filled with other searches running at the same time (so that you can space them out).

View solution in original post

LukeMurphey
Champion

This lookup exists only to provide information as to when searches run. It isn't really used for anything in the app (i.e. isn't used to drive scripts or searches).

The main reason it exists is to help people who are writing searches to find times that not filled with other searches running at the same time (so that you can space them out).

jdeer0618
Explorer

Thanks, LukeMurphey. Just what I was looking for.

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...