Splunk Search

How to run a search query with a scheduler (crontab)

YungLee
Engager

I would like to run a search query every few min, how can i do that.

E.g. index = "a" sourcetype = "b"

Any help is appreciated.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Set the schedule to something like this (for every 5 minutes, of every hour of every day etc.)

*/5 * * * *
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...