Splunk Enterprise Security

How to set up cron to run search out of working hours?

woodentree
Communicator

Hello,

We would like to run a correlation search every 15 minutes but only out of working hours. It means from 6pm to 8am on weekdays and 24 hours on weekends. We thought about the cron below:

14-59/15 18-23,0-7 * * *

However, in this case, we do not cover 8am-6pm scope on weekends, which is not good. Do you have an idea which cron we should use?

Thanks for the help.

0 Karma
1 Solution

nickhills
Ultra Champion

One option is schedule two searches - one for weekdays, and one for weekends.
14-59/15 18-23,0-7 * * 1-5 for weekdays
and
14-59/15 * * * 6-7 for weekends

If my comment helps, please give it a thumbs up!

View solution in original post

gcusello
Legend

Hi @woodentree,
the easiest way is to use a cron every 15 minutes ( */15 * * * * ) and manage the exclusions in the search adding to the main search:

(NOT (date_wday=Sunday OR date_wday=Saturday) date_hour>17 date_hour<8)

but in this way you don't manage the holydays.

To manage holydays, you have to create a calendar lookup and use it for the exclusions.

Ciao.
Giuseppe

woodentree
Communicator

Hi @gcusello,

Thanks for the help.

I’m afraid it will not work for us. Most of our correlation searches uses tstats with avg , sum or count functions.

0 Karma

nickhills
Ultra Champion

One option is schedule two searches - one for weekdays, and one for weekends.
14-59/15 18-23,0-7 * * 1-5 for weekdays
and
14-59/15 * * * 6-7 for weekends

If my comment helps, please give it a thumbs up!

woodentree
Communicator

Hi @nickhillscpl ,

Appreciate your help.

It could be a workaround but I’m afraid not the best one for our circumstances. It will add an additional complexity to maintain a third party inventory tool we have to list our searches in, to set up reporting for management, etc.). Do you know if there is a way to do it in one search?

Thanks.

0 Karma

nickhills
Ultra Champion

In that case, use the solution below from @gcusello !

If my comment helps, please give it a thumbs up!
0 Karma

woodentree
Communicator

Like I've just answered to @gcusello, it looks like it will not be possible for our searches 😞

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...