Splunk Search

How to set a report hourly for time frame between 26th to 5th of each month?

wanda619
Path Finder

How to set a report hourly for time frame between 26th to 5th of each month?

Labels (3)
0 Karma

johnhuang
Motivator

Unclear if you want to schedule your report or filter your data using those dates.

 

The following cron schedule/expression will schedule your report to run every hour between those dates:

 

 

0 * 1-5,26-31 * *

 

 

If you're looking to filter the data in your search to only include those date: 

 

| eval dayofmonth=strftime(_time, "%e")
| search dayofmonth>25 OR dayofmonth<6

 

 

wanda619
Path Finder

@johnhuang  if we want to set the alert for 365 days a year,  hourly? how to acheive that?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

0 * * * *

this will run alert on every hour on every day including those years which have something else than 365 days.

You could test these on  https://crontab.guru/#0_*_*_*_*

r. Ismo

wanda619
Path Finder

@isoutamo is their a way to limit this alert once per day? I tried using throttle and supressing it for once a day.  is thier some other way? 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you want check it only once a day just switch wanted hour to the second * like

0 10 * * *

You should test these with https://crontab.guru/ which told to you what those are meaning.

0 Karma

jdunlea
Contributor

Set your cron scheduled as follows for the scheduled report and it should work.

 

0 */1 1,2,3,4,5,26,27,28,29,30,31 * *

wanda619
Path Finder

@jdunlea if we want to set the alert for 365 days a year,  hourly? how to acheive that?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...